Threat Bulletin 0955: HTTP/2 rapid reset against a sports betting platform in Central Europe

On Saturday 26 October 2024 at 11:09 UTC, a HTTP/2 rapid reset targeted a sports betting customer in Central Europe. The attack peaked at 698.5 million requests per second and lasted 112 minutes. Traffic originated from 1750 autonomous systems in 11 countries, predominantly hijacked home routers.

Vector HTTP/2 rapid reset
Peak 698.5 million requests per second
Duration 112 min
Time to mitigation 0.412 s
Attack traffic reaching origin 0.056%
Legitimate traffic challenged 0.13%

Timeline

The attack was preceded by a publicly announced sales event. Request rates on the targeted routes exceeded their hourly baseline by a factor of 656 within 32 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

A brief increase in p99 latency of 183 ms during the first minute, then normal service.

Recommendations

  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Enable log streaming to your SIEM for faster correlation.
  • Add a dedicated rate limit for the targeted route.

4 thoughts on “Threat Bulletin 0955: HTTP/2 rapid reset against a sports betting platform in Central Europe”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top