SecNews shares the GRNET/EDYTE press release regarding the attack on the Topic Database. As our research team had emphasized from the beginning, GRNET should have made public the part of the publicly available technical data they have at their disposal (since all of the technical data will be made available to the authorities for their investigation).
Furthermore, we had mentioned in our relevant article, but also in what we quoted on Twitter that beyond politicking and interpretations by ignorant journalists and politicians on panels in view of elections, it would be right to seek the opinion of experts, since it was in no way a matter of political exploitation. The issue concerned the conduct of the exams, butalso the infrastructure of the Greek internet which hosts a large number of information systems and not only the Topic Bank.

By reading the public statement of the Greek National Institute of Public Health in detail, we largely confirm what we stated in our original article, but with some additions that particularly concern us.
We quote the full announcement of the Greek National Institute of Health (EDYTE)
What does EDYTE say regarding the DDoS attack on the Topics Bank?
The trapeza.iep.edu.gr platform of the Institute of Educational Policy (IEP) is hosted in EDYTE infrastructure and is connected to the Internet through the EDYTE network. Following the request of the IEP, actions were taken to address distributed denial of service (DDoS) attacks in the morning hours of May 29 and 30, 2023.
See Also: Announcement of strategic partnership between Trust-IT LTD and Cloudflare Inc.
Background: On Monday 29/5, systems widely distributed in countries around the world were creating excessive connections to the platform (TCP SYN flood, approximately 280,000 network packets per second) as well as large idle network traffic (UDP flood) of up to 1.8 Gbps. These attacks were addressed at 09:20.

On Tuesday 30/5, a multi-intensity attack with a large dispersion was carried out against the platform infrastructure (TCP SYN flood) at a rate of up to 5 million network packets per second. The attack was dealt with at 07:32. Then, the target of the attack shifted to the infrastructure of the Panhellenic School Network (PSD) but at 08:09 this too was dealt with. Subsequently, EDYTE contributed to the resolution of other issues that arose due to the attack on the application.
See Also: Topic Bank: Why isn't the major DDoS attack listed on Cloudflare Radar?
Regarding the protection provided by AKAMAI: The AKAMAI platform is designed to protect only the application, not the underlying infrastructure as incorrectly stated in publications. A DDoS attack can be carried out in different ways through the various layers of the Internet protocol stack. Access to the application initially passes from the Internet to the EDYTE network, then to the infrastructure and finally to the application. The attacks on Monday 29/5 were mainly against the application and on Tuesday 30/5 against the infrastructure. As we mentioned, the AKAMAI platform does not protect at the infrastructure level but at the application level. In order to protect the infrastructure, relevant actions were taken by EDYTE engineers at the request of the application administrators.
Countering network attacks: Network-level attacks have been increasing worldwide in recent times. The network destination trapeza.iep.edu.gr that was attacked is only one of hundreds of thousands of potential targets served through the EDYTE network. In any case, however, the specific attacks were successfully countered and, despite the truly unpleasant delays that occurred, they did not manage to prevent the operation of the Topic Bank application.
See Also: DDoS Attack Topic Bank: Technical Analysis Conclusion
Attack documentation: The following publicly available graphs (Figures 3 and 4) show the gradual and smooth increase in traffic on 31/5 and 1/6 where no attack was detected. The smooth traffic gradually increases to a maximum during the day and gradually subsides. On the contrary, in the morning hours of 29/5, malicious traffic is detected as a distinct peak earlier than the smooth peak of traffic. On 30/5, the increase due to malicious traffic clearly exceeds the total traffic of the EDYTE network to the Internet. In Figures 1 and 2, the attack is seen focused as an increased rate of processing network packets entering from the Internet at the “NHRF” and “KOLETTI” nodes respectively.
We note that the diagnosis of attacks is done through network monitoring tools and through reports from protection tools and not only through publicly available data. The data that EDYTE has is clearly available to the criminal investigation being conducted for the case.




Clarifications regarding legitimate network traffic: The rate of 280 thousand packets per second reported for Monday 29/5 corresponds to approximately 17 million connections per minute or 1 billion per hour. On Tuesday 30/5, the corresponding network packet processing rates, as shown indicatively in the above graphs, are 300 million per minute or 18 billion per hour. These rates far exceed the logical requirements for the legitimate traffic of the applications involved in these attacks. We consider comments that suggest oversizing systems as a way to deal with DDoS attacks, or that compare applications with different specifications, to be careless and misleading, especially when they come from representatives of the IT and communications sector.
General comment: We believe that directly or indirectly questioning the credibility of those responsible for diagnosing and responding to such malicious attacks, instead of condemning those who plan and execute them, is counterproductive and risks encouraging them instead of discouraging them by disorienting the discussion.
Technical Interpretation – Commentary – Questions


- According to the announcement, in the first phase of the attack, i.e. on 29/5, the CONNECTIONS to the platform were 280,000 pps (network packets per second). According to charts from both AKAMAI and Cloudflare, the largest cyberattacks recorded worldwide are in the order of Mpps or Tbps , i.e. in the order of millions of packets per second (e.g. 3.47Tbps and not thousands of packets per second as in the case of the Topics Bank. An example of a very powerful DDoS attack in 2020, it was 754 MILLION pps (network packets). In no case can they be compared to the 280,000 pps that the media reported for the current cyberattack. Therefore, according to the announcement, the fact that YES there was a cyberattack but NOT on the scale that was presented continues to apply.
- On the second day on 30/5, according to the announcement, there was an increase of 5 million packets per second, i.e. 5 Mpps. This number is increased, but again NOT at the levels presented to us in the announcements and in the media by the politicians who took on the role of cyber security experts. Indicatively, we mention that in 2018, in an attack on Github we had 1.3Tbps (Tera), in 2016 in a massive attack on the DNS provider Dyn, malicious users had reached 1.5Tbps (Tera), in 2020 in Amazon 2.3 Tbps, in 2017 in Google 2.54Tbps and in Azure in 2021 in a DDoS attack against a single Microsoft customer in Asia the attack was 3.47Tbps with 350Mpps (i.e. 70 times more powerful than the current one). With a simple search, anyone can find out what are considered "strong DDoS attacks" according to international media and organizations.
- It is worth mentioning at this point that ISP Providers, Gaming/Betting services, Telecommunications providers, Banks and media often receive much larger attacks than the referred to as “giant cyberattack” that hit the Bank of Issues. With the difference that all of the above in their majority (unlike government systems) have taken additional measures to prevent such attacks.
- Regarding the comments about AKAMAI, it is correct that it is mentioned in the announcement. However, AKAMAI has a number of products including DDOS Protection Prolexic (with a capacity of over 20TBps for DDOS attacks). From the announcement it is clear that the product in question was not activated by the Topic Bank, and probably only the Web Application Firewall (WAF) was activated to protect only the application. It is worth mentioning, however, that on the first day of the attack, there was NOT even the AKAMAI Web Application firewall (i.e. the application protection) which was added on the first day. NO countermeasures were taken against cyberattacks by the administrators of the application (i.e. the Institute of Educational Policy) and everything that was done with AKAMAI was done after the first day of the attack.
- The National Security Agency (EDYTE) states in the announcement that on Tuesday 30/5 (i.e. after the addition of the AKAMAI WAF) the attack shifted to the school network infrastructure (PSD). Let us remember at this point that the School Network has fallen victim to cyberattacks in the past , and even by Greek hackers, however, no one seems to have taken action and no measures were taken.
- In the diagrams of EDYTE and mainly in those referred to in the images above (images 4+5) with annotations from us: We clearly see that:
- In figure 4, the malicious traffic is somewhat increased compared to the daily normal traffic recorded by GRNEt/EDYTE. In conclusion – It was not the volume that created a problem in the Topic Bank BUT the application itself that was unable to respond to a relatively increased volume of requests.
- The attack points are shown in pps within the red box. Within the purple box (which we added) in Figure 5 is the smooth normal traffic. The arrow shows the difference between the two extreme values (DDoS attack and smooth traffic). It is almost half compared to the upper limit that appears at the time of the cyberattack. So, in comparison, the pps were about twice as high as the daily smooth traffic. And the application could not respond…
- In its announcement, the EDYTE states that it has additional information which it will properly share with the authorities conducting the criminal investigation to identify the perpetrators. The volume and methodology of the cyberattack (small number of packets per seconds), the incorrect and incomplete study of the target, the immediate change of targeting after the addition of the AKAMAI WAF with a new target on the school network does NOT indicate targeting by international hacking groups (KILLNET and other theories mentioned). It indicates individuals with low expertise, a limited budget for renting ddos booter/stresser tools (can be done with very little money) who intended to create a mini-panic. They succeeded NOT because of the high level of expertise, the supposedly high budget (theories of around 200,000 euros) but because of the lack of planning and countermeasures in the creation, maintenance and management of the trapeza.iep.edu.gr application by the competent body of the Institute of Educational Policy. We estimate that the investigation by the authorities will soon yield results for the identification of the perpetrators. It should not impress us if they are teenagers or students, since similar events have occurred in Greece in the past and abroad ...

Regarding the general conclusion about questioning the reliability, it is worth mentioning that unlike other media outlets, SecNews NEVER questioned the reliability of EDYTE and the technicians working there, since we approach the issue from a purely technical perspective. On the contrary, it tried to highlight that GRNET bore no responsibility regarding the containment of the cyberattack, but only the administrators/owners of the application.
What was questioned were the measures taken by the owner of the application (Institute for Educational Policy) as well as the reporting/creation of fear by the media and politicians about an extensive cyberattack that had never before appeared in Greece..
Last Minute Note:According to information from SecNews, it appears that after the attack on the Topics Bank, the EDYTEtook targeted and immediate technical actions to fully protect the Panhellenic Secure Transmission System (SAM/STS) from DDoS attacks using appropriate configuration (Anycast/GRE Tunnel). Until that moment, the Ministry of Education system in question could not respond to medium or large-scale DDoS attacks. Another confirmation that when they seek the opinion of specialized technocrats and technicians who are heard at the highest levels of Organizations and Ministries, worse situations can be prevented…
Source of announcement: grnet.gr
