On Tuesday 18 October 2022 at 03:03 UTC, a ACK flood targeted a news publisher customer in Iberia. The attack peaked at 99.5 Gbps and lasted 8 minutes. Traffic originated from 1690 autonomous systems in 11 countries, predominantly mobile carrier ranges.
| Vector | ACK flood |
| Peak | 99.5 Gbps |
| Duration | 8 min |
| Time to mitigation | 0.376 s |
| Attack traffic reaching origin | 0.082% |
| Legitimate traffic challenged | 0.29% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 39 points of presence.
What the customer saw
Checkout conversion was unchanged compared with the same hour of the previous week.
Recommendations
- Review allow-listed partner ranges quarterly.
- Enable log streaming to your SIEM for faster correlation.
- Lower challenge thresholds on authentication endpoints during high-risk events.
The billing model is what got our finance team on board, honestly.
Could you share the dataset behind the percentages?
Clear and practical, thanks.
Is the risk score exposed in the logs so we can build our own dashboards on it?
Good question. We will cover that in a follow-up post.
How do you avoid challenging uptime monitors and partners?
Great to hear, thanks for sharing your experience.