Cloudflare claims to have prevented record-breaking Distributed Denial of Service (DDoS) attacks.
Last week, the internet architecture provider claimed to have blocked “hundreds” of hyper-volumetric DDoS attacks – which are vastly larger than typical DDoS attacks, often exceeding one terabit per second (Tb/s), in an attempt to take down entire networks and cloud environments.
Among the intense attempts were attacks reaching peaks of 51 billion packets per second (PPS) and 11.5 Tb/s.
The latter attack lasted just 35 seconds, with Cloudflare likening it to a UDP flood, where user datagram protocol packets (UDPs) are used to overwhelm a targeted server or network, making it unavailable to legitimate users. In social media posts outlining the incident, Cloudflare said the traffic mainly came from a combination of IoT and cloud providers, with a post on X saying the UDP deluge "mainly came from Google Cloud."
Cloudflare detailed in an earlier blog that it mitigates such attacks by dropping all UDP traffic unrelated to the Domain Name System at the network edge, ensuring that malicious traffic does not reach its intended target.
This 11.5 Tb/s attack surpassed Cloudflare's previous record of 7.3 Tb/s, set only a few months earlier. The vendor had also reported attacks reaching 6.5 Tb/s and 4.8 billion Bpps in April, in a worrying trend of ever-increasing DDoS attacks.
Following the latest incidents, Cloudflare’s co-founder and CEO, Matthew Prince, was defiant in his evaluation of how the company’s architecture handled the influx of attacks, saying: “We can easily stop this volume of attacks … it’s such a nothingburger for us, I don’t hear about it until we blog about it.”
While Cloudflare proudly touts its ability to take down some of the largest DDoS attacks, the firm is building out capabilities to prevent an emerging attack front: Shadow AI. The vendor added new offerings to its Cloudflare One platform in August, designed to tackle problematic AI use on the network, giving security teams the ability to block unauthorized AI applications and restrict the types of data that can be uploaded to them.
Attacks get bigger, but a leading cause could be on ice
Cloudflare’s handling of such sizable threats comes as DDoS attacks are becoming increasingly more complex.
A June report by Nexusguard revealed that while the number of DDoS attacks only saw a marginal increase of 2%, the average attack size surged by 69%, with peak sizes reaching 962.2 gigabits per second (Gb/s).
That report cautioned of the rising threat of botnets, or interconnected devices infected and operated by a bad actor – a warning echoed in Cloudflare’s findings of the recent attacks, given the involvement of IoT systems.
Systems like RapperBot (also known as Eleven Eleven Botnet or CowBot) specifically target IoT devices like network video recorders (NVRs) of Wi-Fi routers to support attacks by infecting them and forcing them to send large volumes of traffic to targets.
Network operators fearful of RapperBot can breathe a slight sigh of relief after a 22-year-old man from Oregon, and alleged RapperBot administrator, was charged last month.
Ethan Foltz of Eugene is alleged to have been part of a group that monetized RapperBot, offering the botnet in a DDoS-for-hire scheme that targeted victims in over 80 countries, including a U.S. government network and several U.S. tech companies. A criminal complaint suggests that from April to August, Rapperbot conducted more than 370,000 attacks.
Comments