On Thursday 30 May 2024 at 17:21 UTC, a SYN flood targeted a ticketing customer in the UK. The attack peaked at 159.4 Gbps and lasted 20 minutes. Traffic originated from 4026 autonomous systems in 93 countries, predominantly residential proxy networks.
| Vector | SYN flood |
| Peak | 159.4 Gbps |
| Duration | 20 min |
| Time to mitigation | 0.254 s |
| Attack traffic reaching origin | 0.020% |
| Legitimate traffic challenged | 0.30% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 24 points of presence.
What the customer saw
A brief increase in p99 latency of 172 ms during the first minute, then normal service.
Recommendations
- Add a dedicated rate limit for the targeted route.
- Keep origin IPs out of public DNS history.
- Enable authenticated origin pulls.
Clear and practical, thanks.
How do you avoid challenging uptime monitors and partners?
Solid runbook advice. The DNS-at-2am point hit home.
Verified good bots and allow-listed partners bypass challenges entirely.
Clear and practical, thanks.
Great to hear, thanks for sharing your experience.