On Friday 27 January 2023 at 05:23 UTC, a GRE flood targeted a developer platform customer in North America. The attack peaked at 82.6 Gbps and lasted 78 minutes. Traffic originated from 613 autonomous systems in 114 countries, predominantly hijacked home routers.
| Vector | GRE flood |
| Peak | 82.6 Gbps |
| Duration | 78 min |
| Time to mitigation | 0.525 s |
| Attack traffic reaching origin | 0.063% |
| Legitimate traffic challenged | 0.43% |
Timeline
The attack was preceded by a breaking political story. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 18 points of presence.
What the customer saw
A brief increase in p99 latency of 71 ms during the first minute, then normal service.
Recommendations
- Lower challenge thresholds on authentication endpoints during high-risk events.
- Keep origin IPs out of public DNS history.
- Enable log streaming to your SIEM for faster correlation.
Any plans to support per-tenant limits keyed on a JWT claim?
Would love a follow-up on how you handle HTTP/3 fingerprinting.
How does the proof-of-work challenge behave on older Android devices? Any numbers below Android 10?
Verified good bots and allow-listed partners bypass challenges entirely.
Nice to read a vendor blog that admits what went wrong.
Solid runbook advice. The DNS-at-2am point hit home.
Great write-up. We saw almost the same pattern on our login endpoint last month.