Election traffic and attack patterns under the microscope

During the 2022 US midterm election cycle, Cloudflare's Athenian Project and Cloudflare for Campaigns provided security coverage for state and local election infrastructure, political campaigns, and state parties. Traffic and attack data from Cloudflare Radar offers a look at what those sites faced between October 1 and November 8, 2022.

Both programs saw overall traffic climb as Election Day neared, with SQL injection (SQLi) and HTTP Anomaly attacks making up the largest share of WAF-mitigated requests. Notably, most observed attack traffic originated from US-based IP addresses.

Athenian Project sites

For Athenian Project participants — state and local government election sites — daily peak traffic roughly doubled over the course of October, following a clear weekday/weekend rhythm. The most significant growth arrived on Monday, November 7, and Election Day itself. November 7 peaks were just under twice October's levels. On November 8, two distinct peaks appeared: one just under four times October's peaks at 1300 UTC (0800 Eastern, 0500 Pacific), aligning with East Coast poll openings, and another just above four times at 0400 UTC (2300 Eastern, 2000 Pacific), coinciding with West Coast poll closings.

The aggregate numbers obscure some variation. The second Election Day spike was amplified by an outsized surge to a single customer's site, though traffic growth stretched across multiple sites. Still, the pattern confirms voters flocked to local government sites for authoritative election information.

BLOG-1604 Embedded Image - KGKTt0

WAF-mitigated attack traffic stayed largely flat through October and into November, with one clear exception. On Monday, October 10, a rate-limited attack targeted a single Athenian Project participant.

BLOG-1604 Embedded Image - XDV0W1

SQLi attacks grew markedly in the week and a half before Election Day, with an earlier spike on October 24. The final weekend of October saw heavy SQLi activity, while the weekend of November 5-6 was comparatively calm. Attacks ramped up again into Election Day.

BLOG-1604 Embedded Image - YzcISS

HTTP Anomaly attacks also increased in the week leading up to November 8, though less dramatically than SQLi. The largest HTTP Anomaly spikes appeared on October 31/November 1 and just after midnight UTC on November 4 (late afternoon/evening in the US). Related request volume grew steadily into Election Day without major short bursts. The graph also shows a notable but brief attack on October 10, occurring hours after the rate-limited event — it's unclear whether they were connected.

BLOG-1604 Embedded Image - cQbIEY

Across the full survey window, SQLi and HTTP Anomaly categories accounted for just over two-thirds of all WAF-mitigated requests. Nearly 14% fell under "Software Specific," covering attacks tied to particular CVEs. The remainder was split among File Inclusion, XSS (Cross Site Scripting), Directory Traversal, and Command Injection rules.

Despite media reports of foreign election interference, more than 95% of mitigated requests targeting Athenian Project sites geolocated to US IP addresses. That likely reflects attackers leveraging compromised systems and proxies inside the US rather than the attackers' physical locations.

Cloudflare for Campaigns sites

Candidate sites participating in Cloudflare for Campaigns saw traffic build earlier than government sites. Peak volumes rose roughly 50% starting October 12, with another 50-100% increase a week later. Activity slackened toward month's end, then surged again into and on Election Day.

As with the Athenian Project data, one outlier site drew far more traffic than the rest. Other participating sites showed similar directional shifts, but their numbers were dwarfed in aggregate.

BLOG-1604 Embedded Image - 7EZFrV

WAF-mitigated traffic for campaign sites tracked overall traffic closely. Attack volume began climbing around October 19, with another ramp near the end of the month. A spike on October 27 traced to a single customer's site, addressed via Cloudflare's "Security Level" ruleset, which relies on IP reputation to determine whether to challenge requests.

BLOG-1604 Embedded Image - tSG6GL

For candidate sites, HTTP Anomaly and SQLi together made up nearly three-quarters of mitigated requests, with Directory Traversal just under 10%. Compared to Athenian Project participants, campaign sites saw higher proportions of HTTP Anomaly and Directory Traversal attacks, with a slightly lower SQLi share.

BLOG-1604 Embedded Image - lLftir

US IP addresses still dominated, but to a lesser degree — 55% of attacks against campaign sites, versus 95% for Athenian Project participants. The remainder came from a long tail of countries, including Germany, Canada, and the UK among the top five. Again, attackers could be operating from anywhere, routing through botnets or compromised hosts in those countries.

Beyond the numbers

Publishing detailed data on threats to election sites helps the organizations running them improve their defenses. For those interested in the underlying traffic and attack intelligence, Cloudflare Radar provides real-time visibility into internet trends.