nanog mailing list archives

Re: Ransom DDoS attack - need help!


From: Lyndon Nerenberg <lyndon () orthanc ca>
Date: Thu, 3 Dec 2015 11:59:23 -0800 (PST)

Afaik, the DDoS is "only" a UDP based one (or much of the attack), you should be able to mitigate
some to much of the damage caused by filled pipes by blocking incomming UDP trafic at your ISP level.

This is the Armada Collective, based on the description. We just went through a round with them. The hardest they were able to hit us peaked at a little under 80 Gbits/second. Primarily DNS and NTP amplification attacks. They also hit our web servers with a little over 80 million requests over a one hour period, and played some games with TCP to try to mess with the protocol stacks on the servers and network gear.

Cloudflare took care of the web attacks. For DDoS, something like Incapsula will take care of the layer 3 stuff. Not cheap, but very effective.

--lyndon


Current thread: