On Thursday 25 November 2021 at 00:31 UTC, a CLDAP reflection targeted a electronics retail customer in Southeast Asia. The attack peaked at 379.9 Gbps and lasted 139 minutes. Traffic originated from 251 autonomous systems in 96 countries, predominantly a rented booter service.
| Vector | CLDAP reflection |
| Peak | 379.9 Gbps |
| Duration | 139 min |
| Time to mitigation | 0.464 s |
| Attack traffic reaching origin | 0.083% |
| Legitimate traffic challenged | 0.30% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 39 points of presence.
What the customer saw
A brief increase in p99 latency of 73 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Add a dedicated rate limit for the targeted route.
- Review allow-listed partner ranges quarterly.
This matches what we see in iGaming around big matches.
Machine-readable ranges are at /ips.json and via the API.
Thanks — sharing this with our on-call team.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
The billing model is what got our finance team on board, honestly.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
The billing model is what got our finance team on board, honestly.