On Saturday 15 April 2023 at 11:00 UTC, a GRE flood targeted a online casino customer in the Nordics. The attack peaked at 348.6 Gbps and lasted 82 minutes. Traffic originated from 3475 autonomous systems in 52 countries, predominantly a headless-browser farm.
| Vector | GRE flood |
| Peak | 348.6 Gbps |
| Duration | 82 min |
| Time to mitigation | 0.659 s |
| Attack traffic reaching origin | 0.062% |
| Legitimate traffic challenged | 0.32% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 32 points of presence.
What the customer saw
A brief increase in p99 latency of 183 ms during the first minute, then normal service.
Recommendations
- Keep origin IPs out of public DNS history.
- Review allow-listed partner ranges quarterly.
- Enable authenticated origin pulls.
Carpet bombing is nasty. Good to see a clear explanation of it.
Machine-readable ranges are at /ips.json and via the API.
Nice to read a vendor blog that admits what went wrong.
Great to hear, thanks for sharing your experience.
Do you publish the edge IP ranges in a machine-readable format?
Machine-readable ranges are at /ips.json and via the API.
Thanks — sharing this with our on-call team.
Great write-up. We saw almost the same pattern on our login endpoint last month.
Our auditors asked for exactly this kind of incident evidence under DORA.
Thanks — sharing this with our on-call team.
Thanks — sharing this with our on-call team.