On Thursday 24 February 2022 at 06:25 UTC, a ACK flood targeted a online casino customer in Latin America. The attack peaked at 310.1 Gbps and lasted 143 minutes. Traffic originated from 720 autonomous systems in 31 countries, predominantly a Mirai-derived IoT botnet.
| Vector | ACK flood |
| Peak | 310.1 Gbps |
| Duration | 143 min |
| Time to mitigation | 0.581 s |
| Attack traffic reaching origin | 0.012% |
| Legitimate traffic challenged | 0.08% |
Timeline
The attack was preceded by a publicly announced sales event. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 15 points of presence.
What the customer saw
A brief increase in p99 latency of 180 ms during the first minute, then normal service.
Recommendations
- Enable log streaming to your SIEM for faster correlation.
- Lower challenge thresholds on authentication endpoints during high-risk events.
- Keep origin IPs out of public DNS history.
Great write-up. We saw almost the same pattern on our login endpoint last month.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
Great write-up. We saw almost the same pattern on our login endpoint last month.
The billing model is what got our finance team on board, honestly.