Threat Bulletin 0109: Slowloris against a B2B SaaS platform in the UK

On Wednesday 28 July 2021 at 03:14 UTC, a Slowloris targeted a B2B SaaS customer in the UK. The attack peaked at 950.7 million requests per second and lasted 166 minutes. Traffic originated from 1934 autonomous systems in 113 countries, predominantly a rented booter service.

Vector Slowloris
Peak 950.7 million requests per second
Duration 166 min
Time to mitigation 0.624 s
Attack traffic reaching origin 0.006%
Legitimate traffic challenged 0.10%

Timeline

The attack was preceded by an extortion email received two days earlier. Request rates on the targeted routes exceeded their hourly baseline by a factor of 450 within 23 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

A brief increase in p99 latency of 116 ms during the first minute, then normal service.

Recommendations

  • Enable authenticated origin pulls.
  • Add a dedicated rate limit for the targeted route.
  • Review allow-listed partner ranges quarterly.

2 thoughts on “Threat Bulletin 0109: Slowloris against a B2B SaaS platform in the UK”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top