DDoS is one of the most serious threats within cyber space, which is very easy to start while difficult to defense. In 2017, CNCERT carried out an in-depth analysis of thousands of DDoS attacks happened in mainland China. We digs deep into such DDoS threat landscape by analyzing resources (C&C servers, bots and reflection servers), grouping attackers and probing into attacks themselves on the basis of thousands of real DDoS incidents collected through the automatic DDoS attack analysis platform. According to related statistics, most of the DDoS attacks were carried out by the mixed multiple means. And we classified the attacks from real IP addresses, subnet spoofing attacks, random spoofing attacks and reflection and amplification attacks, and analyze the percentage of each attack method. What’s more, we worked out the attack rhythms of each attack resource (including bots and reflection servers) in a single incident and used the grouping method to find out whether different attack resources are controlled by the same C&C server. This kind of approach is called probing of attacks. Probing of attacks determines by the way of grouping which bots are controlled by the same C&C server and how many C&C servers there are, so as to better facilitate attribution.