Website Security & Threat Management
Cloudflare blocks 15M rps HTTPS DDoS attack

Cloudflare blocks 15M rps HTTPS DDoS attack

4/27/2022 · Omer Yoachimik, Julien Desgats

What this post added

This post details the technical specifics of a 15.3 million rps HTTPS DDoS attack mitigation. It describes the attack's origin from data centers and a botnet of ~6,000 bots across 112 countries, with traffic originating from specific ASNs like Hetzner and OVH. It explains Cloudflare's autonomous DDoS protection system, including asynchronous traffic sampling, out-of-path analysis, data streaming algorithms for request analysis, conditional fingerprint matching, real-time signature creation with dynamic masking, and the compilation of mitigation rules when activation thresholds are met. It also references a deep-dive technical blog post on autonomous edge DDoS protection.

Read the original post ↗