هذا المحتوى متاح حاليًا باللغة الإنجليزية فقط.
Data and method
All values in this report come from Cloudflare Radar’s public “top attack pairs” data. Values show the percentage share of total mitigated attack traffic in the period. The live globe on our home page uses the same source.
Important
“Origin country” is the location of the IP addresses the attack traffic came from. It says nothing about the attacker’s identity or nationality — botnets, proxies and cloud servers heavily shape this distribution.
Web layer (L7): the busiest routes
Share of mitigated L7 traffic (%)
- Singapore → Israel8.29%
- Singapore → United States4%
- China → United States3.99%
- Netherlands → United States2.99%
- Belgium → United States2.4%
- United States → Canada2.37%
- Germany → United States2.14%
The United States is by far the most targeted country for web attacks: routes targeting it make up roughly 36.5% among the top 40. Data-center-dense countries such as Singapore and the Netherlands leading on the origin side suggests attack infrastructure runs largely on rented servers.
Network layer (L3): Hong Kong stands out
Share of mitigated L3 DDoS traffic (%)
- Brazil → Hong Kong5.57%
- United States → Hong Kong4.17%
- Brazil → United States2.41%
- Chile → Hong Kong2.08%
- Russia → Hong Kong1.82%
- Argentina → Hong Kong1.75%
L3 — targets (top 40 routes)
- Hong Kong 33.1%
- United States 8.7%
Network-layer DDoS looks different: about 33 points of the top 40 routes target Hong Kong. South American countries leading on the origin side is consistent with the density of compromised devices and home networks there.
What it means for our region
Traffic originating in Türkiye appears in the same dataset: 0.74% of L7 traffic toward the United States and 0.42% of L3 traffic toward Hong Kong. L3 traffic from Azerbaijan (0.47%) is also among the top 40. Compromised devices in the region are being used as part of global attack infrastructure.
- Monitor anomalous traffic leaving your own IP ranges — a compromised server may be attacking someone else.
- Protect web applications with rate limiting and bot management.
- Validate your DDoS resilience with controlled tests: DDoS & WAF Security.



