On Thursday 30 November 2023 at 17:59 UTC, a UDP reflection (DNS) targeted a online payments customer in the Nordics. The attack peaked at 255.1 Gbps and lasted 7 minutes. Traffic originated from 3038 autonomous systems in 46 countries, predominantly a headless-browser farm.
| Vector | UDP reflection (DNS) |
| Peak | 255.1 Gbps |
| Duration | 7 min |
| Time to mitigation | 0.589 s |
| Attack traffic reaching origin | 0.047% |
| Legitimate traffic challenged | 0.60% |
Timeline
The attack was preceded by a competitor’s product launch. Edge packet filters identified the flood by source port and payload signature and dropped it at line rate across 19 points of presence.
What the customer saw
Checkout conversion was unchanged compared with the same hour of the previous week.
Recommendations
- Add a dedicated rate limit for the targeted route.
- Review allow-listed partner ranges quarterly.
- Enable authenticated origin pulls.