Threat Bulletin 0643: login endpoint flood against a video streaming platform in the UK

On Sunday 13 August 2023 at 09:42 UTC, a login endpoint flood targeted a video streaming customer in the UK. The attack peaked at 852.0 million requests per second and lasted 45 minutes. Traffic originated from 1027 autonomous systems in 66 countries, predominantly a headless-browser farm.

Vector login endpoint flood
Peak 852.0 million requests per second
Duration 45 min
Time to mitigation 0.504 s
Attack traffic reaching origin 0.036%
Legitimate traffic challenged 0.17%

Timeline

The attack was preceded by no stated motive. Request rates on the targeted routes exceeded their hourly baseline by a factor of 75 within 35 seconds. The risk score of participating clients crossed the challenge threshold automatically and proof-of-work difficulty rose with origin load.

What the customer saw

Checkout conversion was unchanged compared with the same hour of the previous week.

Recommendations

  • Enable log streaming to your SIEM for faster correlation.
  • Add a dedicated rate limit for the targeted route.
  • Review allow-listed partner ranges quarterly.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top