Threat Bulletin 0720: UDP reflection (DNS) against a online payments platform in the Nordics

On Thursday 30 November 2023 at 17:59 UTC, a UDP reflection (DNS) targeted a online payments customer in the Nordics. The attack peaked at 255.1 Gbps and lasted 7 minutes. Traffic originated from 3038 autonomous systems in 46 countries, predominantly a headless-browser farm.

Vector UDP reflection (DNS)
Peak 255.1 Gbps
Duration 7 min
Time to mitigation 0.589 s
Attack traffic reaching origin 0.047%
Legitimate traffic challenged 0.60%

Timeline

The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 19 points of presence.

What the customer saw

Checkout conversion was unchanged compared with the same hour of the previous week.

Recommendations

  • Add a dedicated rate limit for the targeted route.
  • Review allow-listed partner ranges quarterly.
  • Enable authenticated origin pulls.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top