Threat Bulletin 0092: UDP reflection (DNS) against a airline booking platform in Iberia

On Sunday 4 July 2021 at 15:09 UTC, a UDP reflection (DNS) targeted a airline booking customer in Iberia. The attack peaked at 307.8 Gbps and lasted 86 minutes. Traffic originated from 145 autonomous systems in 108 countries, predominantly a rented booter service.

Vector UDP reflection (DNS)
Peak 307.8 Gbps
Duration 86 min
Time to mitigation 0.950 s
Attack traffic reaching origin 0.088%
Legitimate traffic challenged 0.69%

Timeline

The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 32 points of presence.

What the customer saw

A brief increase in p99 latency of 150 ms during the first minute, then normal service.

Recommendations

  • Enable authenticated origin pulls.
  • Keep origin IPs out of public DNS history.
  • Lower challenge thresholds on authentication endpoints during high-risk events.

1 thought on “Threat Bulletin 0092: UDP reflection (DNS) against a airline booking platform in Iberia”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top