Incident Resolution: Zero seconds of customer downtime. 480 Gbps of volumetric UDP carpet-bombing traffic was detected, analyzed, and scrubbed within 850 milliseconds directly on edge line cards.
1. Attack Profile & Telemetry
On August 14 at 21:14 IST, our border Juniper routers detected an instantaneous spike from an ambient 18 Gbps to 480 Gbps across our Airtel and Tata IP transit feeds:
- Vectors: DNS amplification, NTP monlist reflection, and randomized UDP fragmentation.
- Target: An e-sports tournament Minecraft cluster hosted in our Noida data center.
2. Inline Scrubbing vs. Null-Routing
Traditional Indian hosting providers trigger automated BGP blackholing (null-routing) the moment an IP exceeds 20 Gbps, effectively completing the attacker’s objective. HostCraft routes all inbound packets through inline Corero SmartWall hardware scrubbing appliances capable of absorbing 3.2 Tbps without redirecting traffic out of the country.