Jump to content
  • Cloudflare blocks record-breaking 71 million RPS DDoS attack

    alf9872000

    • 402 views
    • 3 minutes
     Share


    • 402 views
    • 3 minutes

    This weekend, Cloudflare blocked what it describes as the largest volumetric distributed denial-of-service (DDoS) attack to date.

     

    The company said it detected and mitigated not just one but a wave of dozens of hyper-volumetric DDoS attacks targeting its customers over the weekend.

     

    "The majority of attacks peaked in the ballpark of 50-70 million requests per second (rps) with the largest exceeding 71 million rps," Cloudflare's Omer Yoachimik, Julien Desgats, and Alex Forster said.

     

    "This is the largest reported HTTP DDoS attack on record, more than 35% higher than the previous reported record of 46M rps in June 2022."

     

    The attacks were launched using over 30,000 IP addresses from multiple cloud providers against various targets, including gaming providers, cloud computing platforms, cryptocurrency firms, and hosting providers.

     

    Increasingly powerful and more frequent DDoS attacks align with Cloudflare's recent DDoS threat report that paints a grim picture:

     

    • the amount of HTTP DDoS attacks increased by 79% year-over-year
    • the number of volumetric attacks exceeding 100 Gbps grew by 67% quarter-over-quarter (QoQ)
    • the number of attacks lasting more than three hours increased by 87% QoQ

     

    71M%20RPS%20DDoS%20attack.png

    Record 71 million RPS DDoS attack (Cloudflare)

     

    Today's news comes after Google's announcement in August 2022 that it blocked a record DDoS attack over the HTTPS protocol against a Google Cloud Armor customer that had reached 46 million RPS.

     

    That was an increase of roughly 80% more than the previous record, an HTTPS DDoS of 26 million RPS mitigated by Cloudflare in June.

     

    Volumetric DDoS attacks had slowly grown in size since 2021 when several botnets began leveraging powerful devices to hit targets with millions of requests per second.

     

    For instance, in September 2021, the Mēris botnet hit Yandex with a 21.8 million RPS attack and previously hammered a Cloudflare customer with 17.2 million RPS.

     

    In reaction to this stream of ever-increasing attacks, the FBI seized dozens of Internet domains and charged six suspects for their involvement in running 'Booter' or 'Stresser' platforms that anyone can use to launch DDoS attacks.

     

    The move was part of a more extensive coordinated international law enforcement operation targeting DDoS-for-hire services dubbed Operation PowerOFF.

     

    Besides seizing such platforms' domains and taking control of their infrastructure (where possible), the FBI is also working with the UK's National Crime Agency and the Netherlands Police to show ads in search engines to people searching for DDoS services.

     

    For instance, when searching for 'booter service,' Google would show an advertisement stating, "Looking for DDoS tools? Booting is illegal."

     

    Source


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...