On Wednesday 18 May 2022 at 06:52 UTC, a HTTP/2 rapid reset targeted a sports betting customer in the Middle East. The attack peaked at 464.1 million requests per second and lasted 188 minutes. Traffic originated from 3810 autonomous systems in 112 countries, predominantly a headless-browser farm.
| Vector | HTTP/2 rapid reset |
| Peak | 464.1 million requests per second |
| Duration | 188 min |
| Time to mitigation | 0.529 s |
| Attack traffic reaching origin | 0.058% |
| Legitimate traffic challenged | 0.44% |
Timeline
The attack was preceded by a ransom note demanding payment in Monero. Request rates on the targeted routes exceeded their hourly baseline by a factor of 559 within 29 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
Checkout conversion was unchanged compared with the same hour of the previous week.
Recommendations
- Add a dedicated rate limit for the targeted route.
- Enable authenticated origin pulls.
- Lower challenge thresholds on authentication endpoints during high-risk events.
Interesting that most attacks are under ten minutes. Our experience is similar.
Is the risk score exposed in the logs so we can build our own dashboards on it?
Our auditors asked for exactly this kind of incident evidence under DORA.
Thanks! Yes — the risk score and its components are included in every log record.
This matches what we see in iGaming around big matches.
Carpet bombing is nasty. Good to see a clear explanation of it.