Threat Bulletin 0421: GRE flood against a ticketing platform in Latin America

On Monday 3 October 2022 at 09:33 UTC, a GRE flood targeted a ticketing customer in Latin America. The attack peaked at 31.2 Gbps and lasted 132 minutes. Traffic originated from 217 autonomous systems in 41 countries, predominantly compromised cloud VMs.

Vector GRE flood
Peak 31.2 Gbps
Duration 132 min
Time to mitigation 0.648 s
Attack traffic reaching origin 0.052%
Legitimate traffic challenged 0.71%

Timeline

The attack was preceded by no stated motive. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 32 points of presence.

What the customer saw

A brief increase in p99 latency of 201 ms during the first minute, then normal service.

Recommendations

  • Enable log streaming to your SIEM for faster correlation.
  • Keep origin IPs out of public DNS history.
  • Review allow-listed partner ranges quarterly.

5 thoughts on “Threat Bulletin 0421: GRE flood against a ticketing platform in Latin America”

  1. We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top