On Saturday 19 August 2023 at 00:06 UTC, a HTTP/2 rapid reset targeted a sports betting customer in the Middle East. The attack peaked at 696.0 million requests per second and lasted 147 minutes. Traffic originated from 3216 autonomous systems in 19 countries, predominantly hijacked home routers.
| Vector | HTTP/2 rapid reset |
| Peak | 696.0 million requests per second |
| Duration | 147 min |
| Time to mitigation | 0.794 s |
| Attack traffic reaching origin | 0.069% |
| Legitimate traffic challenged | 0.07% |
Timeline
The attack was preceded by a publicly announced sales event. Request rates on the targeted routes exceeded their hourly baseline by a factor of 337 within 11 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
A brief increase in p99 latency of 20 ms during the first minute, then normal service.
Recommendations
- Keep origin IPs out of public DNS history.
- Review allow-listed partner ranges quarterly.
- Enable log streaming to your SIEM for faster correlation.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Do you publish the edge IP ranges in a machine-readable format?
Nice to read a vendor blog that admits what went wrong.
Thanks — sharing this with our on-call team.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Is the risk score exposed in the logs so we can build our own dashboards on it?
Nice to read a vendor blog that admits what went wrong.
Verified good bots and allow-listed partners bypass challenges entirely.
Solid runbook advice. The DNS-at-2am point hit home.
Clear and practical, thanks.