FastNetMon, a leading DDoS detection and mitigation solution provider, revealed this week that it identified and helped mitigate an unprecedented 1.5 billion packets per second (Gpps) distributed denial-of-service attack against a major scrubbing vendor in Western Europe.
This assault represents one of the highest packet-rate floods ever publicly disclosed and underscores the growing sophistication of threat actors leveraging large botnets of compromised devices.
Unprecedented Packet-Rate Flood
The attack, which began in the early hours of September 8, consisted primarily of a UDP flood designed to overwhelm the target’s ability to process incoming packets rather than saturate bandwidth.
By directing an astonishing 1.5 Gpps at the vendor’s edge routers and firewalls, the adversaries sought to exhaust state tables, buffer allocations, and CPU cycles.
Unlike high-bandwidth assaults measured in terabits per second, high packet-per-second attacks strike at the hardware and software limits of network equipment, crippling even well-provisioned infrastructures.
FastNetMon’s real-time traffic analysis engine, built on highly optimized C++ algorithms, automatically detected anomalous spikes within seconds of the flood’s onset.
The system immediately generated alerts and triggered mitigation protocols, rerouting malicious traffic through in-line scrubbing appliances and null-routing rogue prefixes.
Botnet of Compromised CPE and IoT Devices
More than 11,000 autonomous system numbers contributed to the flood, including home routers, IP cameras, and other IoT devices hijacked via unpatched vulnerabilities and default credentials.
This vast botnet enabled the adversaries to coordinate multiple attack vectors, making traditional rate-limiting and signature-based defenses ineffective.
Pavel Odintsov, Founder of FastNetMon, emphasized the dangers of weaponizing insecure consumer hardware.
“We’re witnessing a trend where tens of thousands of poorly secured devices can be aggregated into a single, powerful attack tool,” he stated.
Odintsov warned that as more CPE and IoT endpoints come online without robust security controls, packet-per-second DDoS attacks will only grow in scale and frequency.
The incident follows closely on the heels of Cloudflare’s mitigation of an 11.5 Tbps volumetric attack, illustrating a dual-front escalation in both bandwidth and packet-rate dimensions of DDoS threats.
While massive bit-rate floods aim to saturate links, extreme packet rates exploit processing bottlenecks, requiring specialized detection and mitigation strategies.
FastNetMon’s automated system showcases the critical importance of high-speed anomaly detection for packet-rate attacks.
By leveraging continuous traffic baselining and instantaneous threshold adjustments, service providers can swiftly differentiate legitimate spikes from malicious floods.
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates