nanog mailing list archives

RE: Provider-based DDoS Protection Services


From: "Chris Ranch" <CRanch () Affinity com>
Date: Fri, 29 Jul 2005 03:47:45 -0400


Perhaps you could improve your site's survivability by colocating or
otherwise hosting it.  That is, take the T1's out of the picture...  The
economics of DDoS mitigation may change in your favor too.

Changing our policy to not support irc is one of the best things we did.


I've always felt DDoS defense is just part of providing a good network
to my customers.

Chris 
 
Florian Weimer:

* John Neiberger:

Protect thyself how? For DDoS protection to work, the nasty traffic 
must be stopped before it gets to my access circuits. Once it gets 
close enough for me to do anything about it directly it's too late.

It depends.  Quite a few DoS attacks are not based on 
bandwidth saturation or network device overload.  On the 
other hand, if you address the easy ones within your own 
network, the attackers might switch to types which you can't 
deal with on your own. 8-(

Anyway, you should examine *why* you (or your customers) are 
attacked, and address that.  Everything else is likely 
cost-effective.  Of course, this might mean you have to do 
without some revenue if you have customers that are DoS 
magnets for some reason.



Current thread: