Threat Bulletin 0424: SYN flood against a crypto exchange platform in Central Europe

On Friday 7 October 2022 at 19:52 UTC, a SYN flood targeted a crypto exchange customer in Central Europe. The attack peaked at 273.3 Gbps and lasted 60 minutes. Traffic originated from 316 autonomous systems in 68 countries, predominantly a rented booter service.

Vector SYN flood
Peak 273.3 Gbps
Duration 60 min
Time to mitigation 0.275 s
Attack traffic reaching origin 0.042%
Legitimate traffic challenged 0.28%

Timeline

The attack was preceded by a publicly announced sales event. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 12 points of presence.

What the customer saw

A brief increase in p99 latency of 108 ms during the first minute, then normal service.

Recommendations

  • Lower challenge thresholds on authentication endpoints during high-risk events.
  • Review allow-listed partner ranges quarterly.
  • Add a dedicated rate limit for the targeted route.

13 thoughts on “Threat Bulletin 0424: SYN flood against a crypto exchange platform in Central Europe”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top