On Monday 3 October 2022 at 09:33 UTC, a GRE flood targeted a ticketing customer in Latin America. The attack peaked at 31.2 Gbps and lasted 132 minutes. Traffic originated from 217 autonomous systems in 41 countries, predominantly compromised cloud VMs.
| Vector | GRE flood |
| Peak | 31.2 Gbps |
| Duration | 132 min |
| Time to mitigation | 0.648 s |
| Attack traffic reaching origin | 0.052% |
| Legitimate traffic challenged | 0.71% |
Timeline
The attack was preceded by no stated motive. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 32 points of presence.
What the customer saw
A brief increase in p99 latency of 201 ms during the first minute, then normal service.
Recommendations
- Enable log streaming to your SIEM for faster correlation.
- Keep origin IPs out of public DNS history.
- Review allow-listed partner ranges quarterly.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
We moved from a scrubbing provider to always-on last year; time to mitigation went from minutes to basically nothing.
Would love a follow-up on how you handle HTTP/3 fingerprinting.