Threat Bulletin 0162: HTTP POST flood against a municipal services platform in North America

On Monday 11 October 2021 at 13:23 UTC, a HTTP POST flood targeted a municipal services customer in North America. The attack peaked at 172.4 million requests per second and lasted 132 minutes. Traffic originated from 1643 autonomous systems in 95 countries, predominantly residential proxy networks.

Vector HTTP POST flood
Peak 172.4 million requests per second
Duration 132 min
Time to mitigation 0.391 s
Attack traffic reaching origin 0.082%
Legitimate traffic challenged 0.14%

Timeline

The attack was preceded by a hacktivist channel announcing the target. Request rates on the targeted routes exceeded their hourly baseline by a factor of 816 within 19 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

No customer-visible impact. The on-call engineer was notified and acknowledged the incident from the dashboard.

Recommendations

  • Keep origin IPs out of public DNS history.
  • Review allow-listed partner ranges quarterly.
  • Lower challenge thresholds on authentication endpoints during high-risk events.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top