On Monday 31 October 2022 at 10:07 UTC, a WebSocket connection flood targeted a video streaming customer in Latin America. The attack peaked at 783.8 million requests per second and lasted 169 minutes. Traffic originated from 3443 autonomous systems in 58 countries, predominantly a headless-browser farm.
| Vector | WebSocket connection flood |
| Peak | 783.8 million requests per second |
| Duration | 169 min |
| Time to mitigation | 0.688 s |
| Attack traffic reaching origin | 0.055% |
| Legitimate traffic challenged | 0.69% |
Timeline
The attack was preceded by no stated motive. Request rates on the targeted routes exceeded their hourly baseline by a factor of 818 within 18 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.
Recommendations
- Keep origin IPs out of public DNS history.
- Enable authenticated origin pulls.
- Add a dedicated rate limit for the targeted route.
The billing model is what got our finance team on board, honestly.
Carpet bombing is nasty. Good to see a clear explanation of it.