North America network degradation issues

Incident Report for TCPShield

Postmortem

At 18:04 EST, persistent, ongoing complex attacks were hitting 104.234.6.31 for about 2 hours consistently causing widespread issues in Ashburn, VA.

The cause for impact is simple. This is an address that deliberately had lower mitigation sensitivity and thus mitigation efficacy due to the latency requirements for this address and end customer. The result was substantially more attack leakage towards critical infrastructure than should've otherwise been possible.

As a DDoS mitigation provider, we must strike a difficult balance between lowering latency at the cost of mitigation efficacy, while also maintaining uptime (being our main focus). Achieving both these objectives is difficult without trading off one for the other.

At this time, we've quarantined this address and configured it for highest sensitivity, which has subsided impact in North America immediately. Our response time for this incident could've been substantially better and we thank all enterprise customers who phoned the emergency line at the time.

Posted Apr 14, 2025 - 00:23 UTC

Resolved

From 18:04 EST to 20:00 EST, we observed a series of performance degradation events towards Ashburn VA. The core issue has been resolved and a post mortem follows.
Posted Apr 13, 2025 - 23:30 UTC