Carpet bombing detection
Catch carpet bombing across the whole prefix
A carpet bombing attack spreads its traffic across hundreds or thousands of your addresses. No single host crosses its limit, while your uplinks fill up. Heimnull adds up the traffic to every host in a hostgroup, every second, and flags the attack when the sum crosses the group's limits.

Why per-host limits miss it
Spread 4 Gbps across a /22 and each of its 1,024 addresses receives about 4 Mbps. Against a per-host limit of 2 Gbps, none of them looks attacked, yet your uplinks carry the full 4 Gbps.
Attackers use this on purpose, often against providers and hosting networks whose customers share a prefix. Detection that only looks at single hosts sees nothing until the links are already full.
How Heimnull catches it
Limits on the sum
Every hostgroup can have aggregate limits as well as per-host ones, on the same metrics: bits, packets and flows; TCP, UDP, ICMP and other; SYN, fragments and amplification. They're evaluated every second, in each direction, with the same rule as hosts: over the limit for three evaluations in a row.
Recorded as carpet bombing
When a group crosses its limit and no single host in it crossed its own, the attack is recorded as carpet bombing, with the hosts it hit hardest and its sources, networks, countries, ports and packet sizes.
Baselines for the whole group
Heimnull learns each group's usual traffic for every hour of the week, so an attack on a quiet night stands out too. Baselines start in observe mode: they record what they would have flagged until you trust them.
Tune against your own history
While you edit a hostgroup, Heimnull replays the proposed limits over up to 90 days of recorded peaks and shows how many attacks they would have flagged, and when.
Aggregate limits start off, because the right values depend on the size and traffic of each group. The tuning preview is the quickest way to pick them.
Mitigating a carpet bombing attack
A carpet bombing attack can't be stopped one /32 at a time. Heimnull can announce a FlowSpec rule or a blackhole for the attacked prefix instead, but because one route then covers many addresses, it takes more than a default:
- An explicit switch per hostgroup, separately for FlowSpec and for blackholes, with a warning and a confirmation.
- A minimum prefix length: /24 for IPv4 and /48 for IPv6 by default, so a mistake can't announce a whole aggregate.
- The usual checks: the prefix must be inside your networks, and a blackhole can't cover any whitelisted address.
Until you turn it on, a carpet bombing attack is recorded and notified, with the targets and sources you need to act on it.
On IPv6, it's the default shape of an attack
A single IPv6 /64 holds more addresses than the whole IPv4 internet, so an attack or a scan can touch an endless number of hosts. Heimnull caps the per-host state it keeps, so a sweep across a /64 can't exhaust memory, while the hostgroup's sum still sees all of it. See IPv6 DDoS protection.
Questions
What is a carpet bombing DDoS attack?
A volumetric attack aimed at many addresses in a prefix instead of one. Each address gets a little; together they add up to enough to fill your links. It's built to slip under per-host thresholds.
Will aggregate limits fire on a busy day?
Pick them with the tuning preview, which shows what they would have flagged over your recorded history. Learned baselines follow each hour of the week, and observe mode lets you watch them before they act.
Does it see outbound carpet bombing?
Yes. Aggregates are kept for both directions, so traffic from many of your hosts at once, such as a compromised group of machines, is caught the same way. Outbound attacks only notify by default.
Related
See it on real traffic
The demo runs the full console on made-up traffic, with attacks and mitigations to click through. To try Heimnull on your own network, write to us.
info@heimnull.com