On Friday 24 September 2021 at 16:45 UTC, a UDP reflection (DNS) targeted a gaming community customer in the Middle East. The attack peaked at 313.8 Gbps and lasted 183 minutes. Traffic originated from 1619 autonomous systems in 109 countries, predominantly a headless-browser farm.
| Vector | UDP reflection (DNS) |
| Peak | 313.8 Gbps |
| Duration | 183 min |
| Time to mitigation | 0.456 s |
| Attack traffic reaching origin | 0.034% |
| Legitimate traffic challenged | 0.52% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 16 points of presence.
What the customer saw
A brief increase in p99 latency of 145 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Enable log streaming to your SIEM for faster correlation.
- Add a dedicated rate limit for the targeted route.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Could you share the dataset behind the percentages?
How do you avoid challenging uptime monitors and partners?
Carpet bombing is nasty. Good to see a clear explanation of it.
The point about origin IPs leaking through certificate transparency logs is underrated.