On Sunday 23 May 2021 at 21:35 UTC, a Slowloris targeted a B2B SaaS customer in Western Europe. The attack peaked at 252.5 million requests per second and lasted 148 minutes. Traffic originated from 149 autonomous systems in 101 countries, predominantly a headless-browser farm.
| Vector | Slowloris |
| Peak | 252.5 million requests per second |
| Duration | 148 min |
| Time to mitigation | 0.205 s |
| Attack traffic reaching origin | 0.066% |
| Legitimate traffic challenged | 0.71% |
Timeline
The attack was preceded by a breaking political story. Request rates on the targeted routes exceeded their hourly baseline by a factor of 605 within 25 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
A brief increase in p99 latency of 136 ms during the first minute, then normal service.
Recommendations
- Lower challenge thresholds on authentication endpoints during high-risk events.
- Enable authenticated origin pulls.
- Keep origin IPs out of public DNS history.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.
We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.
Good question. We will cover that in a follow-up post.
Any plans to support per-tenant limits keyed on a JWT claim?
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Great write-up. We saw almost the same pattern on our login endpoint last month.
Thanks — sharing this with our on-call team.