Threat Bulletin 0324: WebSocket connection flood against a healthcare portal platform in the UK

On Sunday 22 May 2022 at 22:57 UTC, a WebSocket connection flood targeted a healthcare portal customer in the UK. The attack peaked at 467.7 million requests per second and lasted 34 minutes. Traffic originated from 828 autonomous systems in 88 countries, predominantly a rented booter service.

Vector WebSocket connection flood
Peak 467.7 million requests per second
Duration 34 min
Time to mitigation 0.913 s
Attack traffic reaching origin 0.053%
Legitimate traffic challenged 0.45%

Timeline

The attack was preceded by a competitor’s product launch. Request rates on the targeted routes exceeded their hourly baseline by a factor of 740 within 31 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

A brief increase in p99 latency of 140 ms during the first minute, then normal service.

Recommendations

  • Enable authenticated origin pulls.
  • Add a dedicated rate limit for the targeted route.
  • Keep origin IPs out of public DNS history.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top