Azure 遭受 15Tbps DDoS 攻击,使用 50 万个 IP 地址。
Azure hit by 15 Tbps DDoS attack using 500k IP addresses

原始链接: https://techcommunity.microsoft.com/blog/azureinfrastructureblog/defending-the-cloud-azure-neutralized-a-record-breaking-15-tbps-ddos-attack/4470422

## Azure成功缓解创纪录DDoS攻击 2025年10月24日,Azure DDoS Protection成功缓解了一次巨大的15.72 Tbps、36.4亿pps DDoS攻击——有史以来在云端记录的最大规模攻击,目标是一个澳大利亚端点。该攻击源自Aisuru僵尸网络(一个强大的物联网网络,利用被入侵的设备如路由器和摄像头),使用了来自超过50万个源IP地址的大量UDP洪水。 Azure全球分布式基础设施和实时检测功能自动过滤并重定向了恶意流量,确保服务不中断。值得注意的是,该攻击的特征——最小的欺骗和随机端口——有助于追踪和缓解工作。 此事件凸显了由更快的互联网速度和物联网设备的激增所驱动的DDoS攻击规模不断扩大。微软敦促用户主动加强DDoS防御,定期模拟攻击,并确保所有面向互联网的应用程序得到充分保护,尤其是在假日季来临之际。

相关文章

原文

On October 24, 2025, Azure DDOS Protection automatically detected and mitigated a multi-vector DDoS attack measuring 15.72 Tbps and nearly 3.64 billion packets per second (pps). This was the largest DDoS attack ever observed in the cloud and it targeted a single endpoint in Australia.

By utilizing Azure’s globally distributed DDoS Protection infrastructure and continuous detection capabilities, mitigation measures were initiated. Malicious traffic was effectively filtered and redirected, maintaining uninterrupted service availability for customer workloads.

The attack originated from Aisuru botnet. Aisuru is a Turbo Mirai-class IoT botnet that frequently causes record-breaking DDoS attacks by exploiting compromised home routers and cameras, mainly in residential ISPs in the United States and other countries.

The attack involved extremely high-rate UDP floods targeting a specific public IP address, launched from over 500,000 source IPs across various regions. These sudden UDP bursts had minimal source spoofing and used random source ports, which helped simplify traceback and facilitated provider enforcement.

Attackers are scaling with the internet itself. As fiber-to-the-home speeds rise and IoT devices get more powerful, the baseline for attack size keeps climbing.

As we approach the upcoming holiday season, it is essential to confirm that all internet-facing applications and workloads are adequately protected against DDOS attacks. Additionally, do not wait for an actual attack to assess your defensive capabilities or operational readiness—conduct regular simulations to identify and address potential issues proactively.

Learn more about Azure DDOS Protection at Azure DDoS Protection Overview | Microsoft Learn

联系我们 contact @ memedata.com