On Monday 10 May 2021 at 05:01 UTC, a GRE flood targeted a online casino customer in Central Europe. The attack peaked at 24.2 Gbps and lasted 100 minutes. Traffic originated from 594 autonomous systems in 93 countries, predominantly a headless-browser farm.
| Vector | GRE flood |
| Peak | 24.2 Gbps |
| Duration | 100 min |
| Time to mitigation | 0.496 s |
| Attack traffic reaching origin | 0.033% |
| Legitimate traffic challenged | 0.49% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 28 points of presence.
What the customer saw
A brief increase in p99 latency of 173 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Review allow-listed partner ranges quarterly.
- Keep origin IPs out of public DNS history.
Thanks — sharing this with our on-call team.
Solid runbook advice. The DNS-at-2am point hit home.
The billing model is what got our finance team on board, honestly.