Məzmuna keç
7/24 Təcili Cavab Xətti
az
Xidmətlər
Həllər
Tədqiqat
Şirkət
AlətlərTrust Center

24 sentyabr 2026Təhdid Hesabatları

Where does attack traffic flow? 24 hours of Cloudflare Radar data

Origin and target country pairs of web (L7) and network-layer (L3) attacks mitigated by Cloudflare between 22 and 23 September 2026.

2 dəq oxuma

Bu məzmun hazırda yalnız ingilis dilində təqdim olunur.

Data and method

All values in this report come from Cloudflare Radar’s public “top attack pairs” data. Values show the percentage share of total mitigated attack traffic in the period. The live globe on our home page uses the same source.

Important

“Origin country” is the location of the IP addresses the attack traffic came from. It says nothing about the attacker’s identity or nationality — botnets, proxies and cloud servers heavily shape this distribution.

Web layer (L7): the busiest routes

Share of mitigated L7 traffic (%)

  • Singapore → Israel8.29%
  • Singapore → United States4%
  • China → United States3.99%
  • Netherlands → United States2.99%
  • Belgium → United States2.4%
  • United States → Canada2.37%
  • Germany → United States2.14%
Domestic traffic (United States → United States, 11.25%) is excluded from the chart.

The United States is by far the most targeted country for web attacks: routes targeting it make up roughly 36.5% among the top 40. Data-center-dense countries such as Singapore and the Netherlands leading on the origin side suggests attack infrastructure runs largely on rented servers.

Network layer (L3): Hong Kong stands out

Share of mitigated L3 DDoS traffic (%)

  • Brazil → Hong Kong5.57%
  • United States → Hong Kong4.17%
  • Brazil → United States2.41%
  • Chile → Hong Kong2.08%
  • Russia → Hong Kong1.82%
  • Argentina → Hong Kong1.75%

L3 — targets (top 40 routes)

  • Hong Kong 33.1%
  • United States 8.7%
The top 40 routes account for about 41.8% of mitigated L3 traffic.

Network-layer DDoS looks different: about 33 points of the top 40 routes target Hong Kong. South American countries leading on the origin side is consistent with the density of compromised devices and home networks there.

What it means for our region

Traffic originating in Türkiye appears in the same dataset: 0.74% of L7 traffic toward the United States and 0.42% of L3 traffic toward Hong Kong. L3 traffic from Azerbaijan (0.47%) is also among the top 40. Compromised devices in the region are being used as part of global attack infrastructure.

  • Monitor anomalous traffic leaving your own IP ranges — a compromised server may be attacking someone else.
  • Protect web applications with rate limiting and bot management.
  • Validate your DDoS resilience with controlled tests: DDoS & WAF Security.

Əhatəni birlikdə müəyyən edək.

Ehtiyacınızı bildirin — mütəxəssislərimiz sizə xüsusi təklif hazırlasın.

Bütün tədqiqatlar