Threat Bulletin 0731: CLDAP reflection against a healthcare portal platform in Iberia

On Saturday 16 December 2023 at 11:17 UTC, a CLDAP reflection targeted a healthcare portal customer in Iberia. The attack peaked at 349.6 Gbps and lasted 33 minutes. Traffic originated from 1430 autonomous systems in 43 countries, predominantly misconfigured open reflectors.

Vector CLDAP reflection
Peak 349.6 Gbps
Duration 33 min
Time to mitigation 0.936 s
Attack traffic reaching origin 0.033%
Legitimate traffic challenged 0.09%

Timeline

The attack was preceded by no stated motive. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 13 points of presence.

What the customer saw

Checkout conversion was unchanged compared with the same hour of the previous week.

Recommendations

  • Add a dedicated rate limit for the targeted route.
  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Keep origin IPs out of public DNS history.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top