On Wednesday 27 July 2022 at 10:16 UTC, a carpet-bombing UDP flood targeted a retail banking customer in Southeast Asia. The attack peaked at 330.8 Gbps and lasted 181 minutes. Traffic originated from 2026 autonomous systems in 49 countries, predominantly residential proxy networks.
| Vector | carpet-bombing UDP flood |
| Peak | 330.8 Gbps |
| Duration | 181 min |
| Time to mitigation | 0.619 s |
| Attack traffic reaching origin | 0.027% |
| Legitimate traffic challenged | 0.03% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 16 points of presence.
What the customer saw
A brief increase in p99 latency of 150 ms during the first minute, then normal service.
Recommendations
- Keep origin IPs out of public DNS history.
- Enable authenticated origin pulls.
- Enable log streaming to your SIEM for faster correlation.
The billing model is what got our finance team on board, honestly.
Do you publish the edge IP ranges in a machine-readable format?
The point about origin IPs leaking through certificate transparency logs is underrated.
We had the exact false-positive issue with CGNAT carriers. The weighting change makes sense.
Nice to read a vendor blog that admits what went wrong.
Is the risk score exposed in the logs so we can build our own dashboards on it?