A Google Cloud Armor customer was hit by a denial-of-service (DDoS) attack over the HTTPS protocol that reached 46 million requests per second (RPS), making it the largest of its kind ever recorded.
In just two minutes, the attack escalated from 100,000 RPS to 46 million RPS, nearly 80% more than the previous record, a 26 million RPS HTTPS DDoS mitigated by Cloudflare in June.
The attack began on the morning of June 1, at 09:45 Pacific Time and targeted the victim's HTTP/S Load Balancer initially with just 10,000 RPS.
In eight minutes, the DDoS attack escalated to 100,000 RPS and Google's Cloud Armor Protection kicked in by generating an alert and signatures based on some data gleaned from traffic analysis.
Two minutes later, the attack peaked at 46 million requests per second:
To see how massive the DDoS attack was at its peak, Google says it was equivalent to taking all daily requests to Wikipedia in just 10 seconds.
See also: Russian botnet RSocks taken down
Fortunately, the customer had already implemented the recommended solution from Cloud Armor which allowed operations to run normally. The attack ended 69 minutes after it began.

"The attacker likely found that it did not have the desired impact, while incurring significant costs in executing the attack," says a report by Google's Emil Kiner (Senior Product Manager) and Satya Konduru (Technical Lead).
The malware behind the DDoS attack has not yet been identified, but the geographic distribution of the services used points to a Mēris, a botnet responsible for DDoS attacks that peaked at 17.2 million RPS and 21.8 million RPS, both records at the time.
Mēris is known for using insecure proxies to send malicious traffic, in an attempt to hide the origin of the attack.
Google researchers say the traffic came from just 5,256 IP addresses spread across 132 countries and forged encrypted requests (HTTPS), indicating that the devices sending the requests have fairly powerful computing resources.
"Although end-to-end encryption was necessary to inspect traffic and effectively mitigate the attack, using HTTP Pipelining required Google to complete relatively few TLS handshakes."
Another feature of the attack is the use of Tor exit nodes to deliver traffic. Although almost 22% or 1,169 of the sources routed requests through the Tor network, they accounted for only 3% of the attack traffic.

However, Google researchers believe that Tor exit nodes could be used to deliver "significant amounts of unwanted traffic to web applications and services.".
See also: New Go botnet Panchan spreads rapidly across educational networks
Starting last year, an era of record- breaking volumetric DDoS attacks began with a few botnets leveraging a small number of powerful devices to hit various targets.
In September 2021, the Mēris botnet hit Russian internet giant Yandex with an attack that peaked at 21.8 million requests per second. Previously, the same botnet pushed 17.2 million RPS against a Cloudflare.
Last November, Microsoft 's Azure DDoS protection platform mitigated a massive 3.47 terabits per second attack at a packet rate of 340 million packets per second (pps) for a customer in Asia.
Another Cloudflare customer was hit with a DDoS reaching 26 million RPS.
Source: bleepingcomputer.com
