Website Security & Threat Management
The Porcupine Attack: investigating millions of junk requests

The Porcupine Attack: investigating millions of junk requests

1/9/2017 · Marek Majkowski

What this post added

This post details the investigation and analysis of the 'Porcupine Attack', a novel threat characterized by millions of junk HTTP requests per second that bypassed traditional HTTP DDoS mitigation systems. It highlights Cloudflare's internal monitoring tools (Grafana), debugging techniques (tcpdump), and the detailed analysis of the malformed HTTP payload, revealing a patterned binary junk. The post also discusses the scale, global geographic distribution, and aggressive IP rotation of the attacking sources, suggesting a sophisticated botnet. It concludes with the identification of the payload generation algorithm and ongoing investigation into the nature of the attack.

Read the original post ↗