On Sunday 22 May 2022 at 22:57 UTC, a WebSocket connection flood targeted a healthcare portal customer in the UK. The attack peaked at 467.7 million requests per second and lasted 34 minutes. Traffic originated from 828 autonomous systems in 88 countries, predominantly a rented booter service.
| Vector | WebSocket connection flood |
| Peak | 467.7 million requests per second |
| Duration | 34 min |
| Time to mitigation | 0.913 s |
| Attack traffic reaching origin | 0.053% |
| Legitimate traffic challenged | 0.45% |
Timeline
The attack was preceded by a competitor’s product launch. Request rates on the targeted routes exceeded their hourly baseline by a factor of 740 within 31 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.
What the customer saw
A brief increase in p99 latency of 140 ms during the first minute, then normal service.
Recommendations
- Enable authenticated origin pulls.
- Add a dedicated rate limit for the targeted route.
- Keep origin IPs out of public DNS history.