On Friday 30 August 2024 at 09:16 UTC, a SYN flood targeted a crypto exchange customer in the Benelux. The attack peaked at 212.8 Gbps and lasted 70 minutes. Traffic originated from 684 autonomous systems in 51 countries, predominantly compromised cloud VMs.
| Vector | SYN flood |
| Peak | 212.8 Gbps |
| Duration | 70 min |
| Time to mitigation | 0.092 s |
| Attack traffic reaching origin | 0.034% |
| Legitimate traffic challenged | 0.29% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 15 points of presence.
What the customer saw
A brief increase in p99 latency of 23 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Add a dedicated rate limit for the targeted route.
- Keep origin IPs out of public DNS history.
The billing model is what got our finance team on board, honestly.
Thanks — sharing this with our on-call team.
How do you avoid challenging uptime monitors and partners?