On Monday 7 February 2022 at 05:19 UTC, a carpet-bombing UDP flood targeted a developer platform customer in Western Europe. The attack peaked at 195.7 Gbps and lasted 108 minutes. Traffic originated from 4173 autonomous systems in 94 countries, predominantly a headless-browser farm.
| Vector | carpet-bombing UDP flood |
| Peak | 195.7 Gbps |
| Duration | 108 min |
| Time to mitigation | 0.394 s |
| Attack traffic reaching origin | 0.021% |
| Legitimate traffic challenged | 0.34% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 20 points of presence.
What the customer saw
A brief increase in p99 latency of 212 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Lower challenge thresholds on authentication endpoints during high-risk events.
- Keep origin IPs out of public DNS history.
Solid runbook advice. The DNS-at-2am point hit home.
Machine-readable ranges are at /ips.json and via the API.
Solid runbook advice. The DNS-at-2am point hit home.
Would love a follow-up on how you handle HTTP/3 fingerprinting.
Clear and practical, thanks.
Great to hear, thanks for sharing your experience.