
1/9/2017 · Marek Majkowski
What this post added
This post details the investigation and analysis of the 'Porcupine Attack', a novel threat characterized by millions of junk HTTP requests per second that bypassed traditional HTTP DDoS mitigation systems. It highlights Cloudflare's internal monitoring tools (Grafana), debugging techniques (tcpdump), and the detailed analysis of the malformed HTTP payload, revealing a patterned binary junk. The post also discusses the scale, global geographic distribution, and aggressive IP rotation of the attacking sources, suggesting a sophisticated botnet. It concludes with the identification of the payload generation algorithm and ongoing investigation into the nature of the attack.