Cloudflare - must be more than a CDN

or, Why is it attempting to connect, by massive swarm, to my server which doesn’t use their services?

You don’t have to read or respond of course, but here it is.
I suppose I could always ask ‘them’.
I do have some related perspective/data which I’ll append as a reply.

Here is a continuous log fragment of time[hh:mm] and quantity(uniq IPs) of incoming new tcp connections which hit my rate limiting:

23:06 (1)
23:07
23:13 (2)
23:14
23:15 (2)
23:16 (18)
23:17 (27)
23:18 (68)
23:19 (102)
23:20 (108)
23:21 (119)
23:22 (102)
23:23 (97)
23:24 (42)
23:25 (17)
23:26 (1)
23:27
23:30 (1)

and my processing …

└─# tail -30 drop.log |awk ‘$2 ~ /23:/ && $5 ~ /[0-9 .]+/’ |tr " " “\n” |sed -nE ‘/[1]{8,}/p’ |sort -Vu |cut -d’.’ -f1-3 |sed -E ‘s/$/.0/24/g’ |aggregate |while read p; do asn $p; done |tee /tmp/swarm-asns

to reveal the source sof this swarm:

└─# awk '{print $3,$13}' </tmp/swarm-asns |sort |uniq -c |sort -n
1 16509 AMAZON-02
1 197540 netcup-AS
1 269843 AS269843
1 37693 OOREDOO
1 395747 CLOUDFLARENET-SFO05
146 14789 CLOUDFLARENET
378 13335 CLOUDFLARENET

count ASN owner

Triggering the rate limit puts the IP into a set which drops further connections for the next two minutes. … which could explain why every logged IP was unique

How did those blocks aggregate?

  1 21
 24 22
 96 23
408 24
count \prefix

How many Class-B’s were involved?

└─# cut -d'.' -f1-2 </tmp/swarm-asns |sort |uniq -c |awk '$1 > 31'
52 104.22
36 104.23
77 162.158
91 172.68
100 172.69
57 172.70
70 172.71


  1. 0-9. ↩︎

Relatedly, … if an IP hits the ratelimit, it gets inserted into set which drops future new connections for 2 minutes; if while in that set, it attempts further new connections at a slightly lower rate limit, I add the IP’s entire prefix (reported by cymru/pwhois) to a semi-permanent blocklist, from which we currently glean …

└─# cut -d’ ’ -f1 <dump.list |sort -u |aggregate |wc -l
304 total prefixes in the list

└─# cut -d’ ’ -f1 <dump.list |sort -u |aggregate |awk -F"/" ‘$2 <= 20’ |wc -l
229 larger than a /21

└─# cut -d’ ’ -f1 <dump.list |sort -u |aggregate |awk -F"/" ‘$2 <= 16’ |wc -l
53 larger than a /17

… of which from the latter …

 30 396982 GOOGLE-CLOUD-PLATFORM
 13 16509 AMAZON-02
  #   ASN

By far the most connect abusive operator I see is from IPs whose PTR is within
bc.googleusercontent.com

Just beneath that, and below my current trigger for semi-permanent blocklist, is

from the .compute*.amazonaws.com space

https://radar.cloudflare.com/as13335?dateRange=28d

Here’s a 24hr. snapshot of related firewall activity (packet counting)

[wide screen formatted]

60:minutes   76:http-new    0:hrated-dropped    0:http-rated   35:dumplist    2:ossec-blocked    0:orated-dropped    0:ossec-rated
60:minutes   45:http-new    0:hrated-dropped    0:http-rated   18:dumplist    7:ossec-blocked   10:orated-dropped    1:ossec-rated
60:minutes   60:http-new    0:hrated-dropped    0:http-rated  131:dumplist   13:ossec-blocked 2129:orated-dropped    3:ossec-rated
60:minutes   53:http-new    0:hrated-dropped    0:http-rated  264:dumplist    5:ossec-blocked    8:orated-dropped    1:ossec-rated
60:minutes   73:http-new    0:hrated-dropped    0:http-rated  144:dumplist   13:ossec-blocked   72:orated-dropped    3:ossec-rated
60:minutes   79:http-new    0:hrated-dropped    0:http-rated   21:dumplist    5:ossec-blocked   11:orated-dropped    1:ossec-rated
59:minutes   72:http-new    0:hrated-dropped    0:http-rated   80:dumplist    5:ossec-blocked   64:orated-dropped    1:ossec-rated
60:minutes   65:http-new   26:hrated-dropped    2:http-rated   76:dumplist    5:ossec-blocked    5:orated-dropped    1:ossec-rated
60:minutes   79:http-new   19:hrated-dropped    1:http-rated   22:dumplist    5:ossec-blocked   29:orated-dropped    2:ossec-rated
60:minutes  324:http-new 2077:hrated-dropped   55:http-rated 1952:dumplist   12:ossec-blocked  274:orated-dropped    6:ossec-rated
60:minutes   65:http-new    0:hrated-dropped    0:http-rated  124:dumplist   10:ossec-blocked   83:orated-dropped    2:ossec-rated
60:minutes   70:http-new    0:hrated-dropped    0:http-rated   39:dumplist    0:ossec-blocked    0:orated-dropped    0:ossec-rated
60:minutes   78:http-new    0:hrated-dropped    0:http-rated  128:dumplist    4:ossec-blocked    0:orated-dropped    0:ossec-rated
60:minutes   88:http-new   52:hrated-dropped   11:http-rated   39:dumplist   11:ossec-blocked 2139:orated-dropped    2:ossec-rated
60:minutes  140:http-new  157:hrated-dropped    8:http-rated   29:dumplist   16:ossec-blocked  328:orated-dropped   12:ossec-rated
60:minutes   80:http-new   71:hrated-dropped    1:http-rated  165:dumplist    4:ossec-blocked    6:orated-dropped    0:ossec-rated
60:minutes   35:http-new    0:hrated-dropped    0:http-rated  118:dumplist    5:ossec-blocked   54:orated-dropped    1:ossec-rated
60:minutes   71:http-new   18:hrated-dropped    1:http-rated  140:dumplist   10:ossec-blocked   43:orated-dropped    2:ossec-rated
60:minutes   60:http-new   24:hrated-dropped    1:http-rated   91:dumplist    0:ossec-blocked    0:orated-dropped    0:ossec-rated
60:minutes   53:http-new    0:hrated-dropped    0:http-rated   76:dumplist    1:ossec-blocked    0:orated-dropped    0:ossec-rated
60:minutes  204:http-new 2907:hrated-dropped   10:http-rated  135:dumplist    0:ossec-blocked    0:orated-dropped    0:ossec-rated
60:minutes 1786:http-new 5669:hrated-dropped  710:http-rated   53:dumplist    1:ossec-blocked    0:orated-dropped    0:ossec-rated
60:minutes   78:http-new    0:hrated-dropped    0:http-rated   90:dumplist   15:ossec-blocked  126:orated-dropped    3:ossec-rated
60:minutes   38:http-new    0:hrated-dropped    0:http-rated   69:dumplist    7:ossec-blocked  231:orated-dropped    1:ossec-rated
43:minutes   55:http-new    0:hrated-dropped    0:http-rated   29:dumplist   14:ossec-blocked  279:orated-dropped    2:ossec-rated


the http/hrated counters are for port 443; the orated/ossec counters are for the Ossec HIDS response system, which utilizes an escalating timeout for its dropset. Extreme values get my attention however.

None of these, or the amazonaws or cloudflare traffic, are likely to be pernicious; but it is surely, and apparently poorly, automated; in service of suspicious ends.

The Net is becoming as unusable as the planet unlivable; both victims of misguided capital.

Meanwhile, …