Monitor icon
Monitor
Network Visibility

DDoS Attacks on Israeli Large Industrial Company

November 11, 2024
 DDoS Attacks on Israeli Large Industrial Company

The Challenge

Target
Large Israeli Industrial Company's IP address
Duration
Over 14 hours
Attack Volume
1Tbps of traffic with more than 2000 different vectors of attacks
Attack Peak
DDoS attack vectors changing frequently

Full Story

On January 17, 2024, just before 2:00 p.m., many alerts began to be received regarding the detection of DDoS attacks on the FlowSec customer’s IP address space.

The attacks included more than 2,000 different vectors, with a capacity of 1 Tbps of malicious traffic that was successfully blocked by FlowSec’s ISP DDoS Protection system. The attacks lasted for more than 14 hours.

The ISP DDoS Protection system detected the attacks and automatically created mitigation signatures, which were then sent to the relevant CSP’s routers.

During the detection phase and signature creation, email alerts were generated for each new signature—over 2,000 in total.

Due to intermittent leaks caused by frequently changing DDoS attack vectors, and in order to optimize and accelerate the protection of the client’s IP address space, the FlowSec team analyzed the traffic patterns and added manual signatures directly to the customer’s networks.

After the DDoS attacks subsided and traffic levels returned to normal, the mitigation signatures were removed from the CSP’s routers according to system configurations.

However, given the volumetric nature of the DDoS attacks, the FlowSec team—together with customer representatives—decided to keep the initiated signatures in place and continue to monitor incoming traffic through the ISP DDoS Protection system.

See below for detailed reports and diagrams of the DDoS attacks.

Graph 1 – Attacks blocked during 14 hours.
Graph 2 – Top Hosts during the attack and the volume of traffic that was blocked

Flowsec Achievements

  • The customer kept working as usual during this massive attack.
  • The system quickly detected the attacks and created signatures that were sent to the CSP’s routers
  • The Uplink Service Provider implemented a BH-type signature created by FLOWSEC to addresses with abnormal traffic of over 2Gbps to a single address

 

Contact Us

Flowsec Ltd.

    Flowsec provides cutting-edge SaaS DDoS protection solutions for ISPs, CSPs, enterprises, MSSPs, and the national security sector. With multi-tenant and global shield technology, Flowsec enables communication service providers to offer advanced DDoS protection services to their customers.

    Accessibility Toolbar