nanog mailing list archives
Re: [SECURITY] Application layer attacks/DDoS attacks
From: "Roland Dobbins" <rdobbins () arbor net>
Date: Tue, 26 May 2015 12:19:58 +0700
On 26 May 2015, at 4:27, Randy Bush wrote:
may i remind you of the dns query flood i had which you helped research?udp and tcp, from the same sources.
Yes - we determined that the TCP-based queries were a result of RRL, which is optimized to help with spoofed reflection/amplification attacks, but isn't intended to handle non-spoofed query-floods (hence S/RTBH, flowspec, IDMS, et. al.) like the particular ANY query-flood directed at your auths.
----------------------------------- Roland Dobbins <rdobbins () arbor net>
Current thread:
- RE: [SECURITY] Application layer attacks/DDoS attacks, (continued)
- RE: [SECURITY] Application layer attacks/DDoS attacks Keith Medcalf (May 25)
- Re: [SECURITY] Application layer attacks/DDoS attacks jim deleskie (May 25)
- Re: [SECURITY] Application layer attacks/DDoS attacks Roland Dobbins (May 25)
- Re: [SECURITY] Application layer attacks/DDoS attacks Roland Dobbins (May 25)
- Re: [SECURITY] Application layer attacks/DDoS attacks Roland Dobbins (May 23)
- Re: [SECURITY] Application layer attacks/DDoS attacks Roland Dobbins (May 25)
- Re: [SECURITY] Application layer attacks/DDoS attacks Randy Bush (May 25)
- Re: [SECURITY] Application layer attacks/DDoS attacks Roland Dobbins (May 25)