Cloudflare Thwarts Largest HTTP DDoS Attack Ever Recorded
Cloudflare has confirmed that it detected and mitigated a series of hyper-volumetric distributed denial-of-service (DDoS) attacks over the weekend, with the largest peaking at over 71 million requests per second (rps). This surpasses the previous publicly disclosed record of 46 million rps, which was reported in June 2022, marking a more than 54% increase in peak attack volume. The majority of the attacks observed during this campaign peaked between 50 and 70 million rps.
The attacks were HTTP/2-based and were directed at websites protected by Cloudflare, including a gaming provider, cryptocurrency platforms, hosting companies, and cloud computing services. The traffic originated from more than 30,000 unique IP addresses spread across multiple cloud providers. Cloudflare has stated that it is collaborating with these providers to dismantle the botnet responsible.

Context and connection to other campaigns: Cloudflare does not believe this weekend's activity is linked to the recent Killnet campaign, which targeted healthcare organizations less than two weeks prior, nor does it attribute the attacks to any event related to the US Super Bowl. The assessment is based on differing attack methods and target profiles.
The Mechanics of HTTP DDoS Attacks
An HTTP DDoS attack aims to overwhelm a target website with a flood of requests, rendering it unavailable to legitimate users. Attributing to a botnet of compromised devices, these attacks can be orchestrated at scale. Botnets require investment and technical know-how to build, but attackers can bypass that barrier using DDoS-as-a-Service platforms, which can be hired for as little as $30 per month.
These attacks are distinct from ransomware in that they do not require system intrusion or a network foothold. They function more like a hit-and-run: the attacker only needs to know the target's website or IP address to launch an assault.
Rising Threat and Attack Trends
Attack frequency and sophistication have escalated over recent months. According to Cloudflare's latest threat report, HTTP DDoS attacks have increased by 79% year-over-year. Additionally, volumetric attacks exceeding 100 Gbps grew by 67% quarter-over-quarter, and the number of attacks lasting longer than three hours rose by 87% quarter-over-quarter. Ransom DDoS attacks, which involve extortion threats without system compromise, also saw a steady increase, peaking in November 2022 when a quarter of surveyed customers reported receiving such a threat.
This campaign originates from a growing trend of attacks launched from cloud providers. To address this, Cloudflare is offering a free botnet threat feed to service providers that own their IP space. This feed supplies threat intelligence specific to their autonomous systems, aiding in the identification and mitigation of attack sources. Providers can join an early access waiting list for this service.
Recommendations for Defender Preparedness
Cloudflare's automated systems detected and mitigated this attack wave without manual intervention. For organizations seeking to optimize their protections, Cloudflare recommends the following steps for its customers:
- Confirm that all
DDoS Managed Rulesetsare set to their default configuration, which includes high sensitivity and mitigation actions. - If subscribed to the Advanced DDoS Protection service, enable
Adaptive DDoS Protection, which uses unique traffic patterns to inform mitigation decisions. - Combine positive and negative security models in
firewall rulesandrate limiting rules, reducing allowed traffic to match known usage. - Ensure origin servers are not directly exposed; access should be restricted to Cloudflare IPs.
- When available, use
Managed IP Listsin firewall rules and consider incorporating bot scores from theBot Managementsubscription. - Implement comprehensive caching to reduce strain on origin infrastructure, and monitor subrequest levels when using Cloudflare Workers.
- Set up
DDoS alertingto facilitate faster response times.
Given the effectiveness of automated detection and mitigation, Cloudflare asserts that these tools are essential, as manual defenses alone are insufficient. The company has offered unmetered, unlimited DDoS protection to all customers since 2017.



