Threat Bulletin 0647: HTTP/2 rapid reset against a sports betting platform in the Middle East

On Saturday 19 August 2023 at 00:06 UTC, a HTTP/2 rapid reset targeted a sports betting customer in the Middle East. The attack peaked at 696.0 million requests per second and lasted 147 minutes. Traffic originated from 3216 autonomous systems in 19 countries, predominantly hijacked home routers.

Vector HTTP/2 rapid reset
Peak 696.0 million requests per second
Duration 147 min
Time to mitigation 0.794 s
Attack traffic reaching origin 0.069%
Legitimate traffic challenged 0.07%

Timeline

The attack was preceded by a publicly announced sales event. Request rates on the targeted routes exceeded their hourly baseline by a factor of 337 within 11 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

A brief increase in p99 latency of 20 ms during the first minute, then normal service.

Recommendations

  • Keep origin IPs out of public DNS history.
  • Review allow-listed partner ranges quarterly.
  • Enable log streaming to your SIEM for faster correlation.

10 thoughts on “Threat Bulletin 0647: HTTP/2 rapid reset against a sports betting platform in the Middle East”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top