法国云公司OVHcloud遭受创纪录840百万PPS DDoS攻击

French cloud computing firm OVHcloud said it mitigated a record-breaking distributed denial-of-service (DDoS) attack in April 2024 that reached a packet rate of 840 million packets per second (Mpps).


This is just above the previous record of 809 million Mpps reported by Akamai as targeting a large European bank in June 2020.


The 840 Mpps DDoS attack is said to have been a combination of a TCP ACK flood that originated from 5,000 source IPs and a DNS reflection attack leveraging about 15,000 DNS servers to amplify the traffic.

据称,840百万数据包每秒的DDoS攻击是由源自5,000个源IP的TCP ACK泛洪和利用约15,000个DNS服务器放大流量的DNS反射攻击组合而成。

“While the attack was distributed worldwide, 2/3 of total packets entered from only four [points of presence], all located in the U.S. with 3 of them being on the west coast,” OVHcloud noted. “This highlights the capability of the adversary to send a huge packet rate through only a few peerings, which can prove very problematic.”

OVHcloud指出:“虽然这次攻击是全球分布的,但三分之二的总数据包只来自美国四个[存在点],其中有三个位于西海岸。” “这突显了对手通过只有少数对等连接发送大量数据包速率的能力,这可能会带来很大的问题。”

The company said it has observed a significant uptick in DDoS attacks in terms of both frequency and intensity starting 2023, adding those reaching above 1 terabit per second (Tbps) have become a regular occurrence.


“In the past 18 months, we went from 1+ Tbps attacks being quite rare, then weekly, to almost daily (averaged out over one week),” OVHcloud’s Sebastien Meriot said. “The highest bit rate we observed during that period was ~2.5 Tbps.”

OVHcloud的Sebastien Meriot表示:“在过去的18个月里,我们从1+ Tbps的攻击相当罕见,然后变成每周一次,然后几乎每天(在一个星期内平均下来)。” “在那段时间内,我们观察到的最高比特率约为~2.5 Tbps。”

Unlike typical DDoS attacks that rely on sending a flood of junk traffic to targets with an aim to exhaust available bandwidth, packet rate attacks work by overloading the packet processing engines of networking devices close to the destination, such as load balancers.


Data gathered by the company shows that DDoS attacks leveraging packet rates greater than 100 Mpps have witnessed a sharp increase for the same time period, with many of them emanating from compromised MikroTik Cloud Core Router (CCR) devices. As many as 99,382 MikroTik routers are accessible over the internet.

该公司收集的数据显示,利用大于100 Mpps的数据包速率进行DDoS攻击在同一时期有了显著增加,其中许多攻击源自受损的MikroTik Cloud Core Router(CCR)设备。多达99,382个MikroTik路由器可以通过互联网访问。

These routers, besides exposing an administration interface, run on outdated versions of the operating system, making them susceptible to known security vulnerabilities in RouterOS. It’s suspected that threat actors are likely weaponizing the operating system’s Bandwidth test feature to pull off the attacks.


It’s estimated that even hijacking 1% of the exposed devices into a DDoS botnet could theoretically give adversaries enough capabilities to launch layer 7 attacks reaching 2.28 billion packets per second (Gpps).


It bears noting at this stage that MikroTik routers have been leveraged for building potent botnets such as Mēris and even used for launching botnet-as-a-service operations.


“Depending on the number of compromised devices and their actual capabilities, this could be a new era for packet rate attacks: with botnets possibly capable of issuing billions of packets per second, it could seriously challenge how anti-DDoS infrastructures are built and scaled,” Meriot said.





速盾高防cdn's avatar速盾高防cdn
上一篇 2024年7月8日 下午12:32
下一篇 2024年7月8日 下午12:36


  • dos攻击全称

    导语 嗨,大家好!作为速盾CDN小编,今天我要和大家聊一聊一个挺麻烦的问题——DOS攻击。没错,你没听错,就是那种会让网站瘫痪的、让人头疼不已的家伙。别担心,我会尽量用通俗易懂的方…

  • 昆明失联,昆明连续失踪80人最新消息

    当谈到SEO 优化的文章时,标题显然是关键。所以我想谈谈最近在昆明发生的一系列奇怪事件和令人困惑的失踪事件。 概述: 引入昆明失踪事件:介绍昆明市80人连续失踪事件,引起社会广泛关…

    DDOS防护 2024年5月15日
  • 上线运营近 28 年后,ICQ 官宣 6 月 26 日关闭

    DoNews5月25日消息,ICQ 官宣将于 2024 年 6 月 26 日关闭,在上线运营近 28 年之后走向终结。 在 QQ 和微信出现之前,ICQ 风靡全球,超过 1 亿用户…

    DDOS防护 2024年5月25日
  • 网站域名被劫持怎么处理

    标题:网站域名被劫持怎么处理 导语: 你好,亲爱的读者们,我是速盾CDN小编。今天,我们将探讨一个令人头疼的问题:当你发现自己的网站域名被劫持时,应该采取哪些措施来解决这个困扰?域…



您的邮箱地址不会被公开。 必填项已用 * 标注