nanog mailing list archives
Re: Ransom DDoS attack - need help!
From: "Roland Dobbins" <rdobbins () arbor net>
Date: Fri, 04 Dec 2015 11:09:02 +0700
On 4 Dec 2015, at 9:34, alvin nanog wrote:
all that tcpdump jibberish
Is entirely unnecessary, as well as being completely impractical on a network of any size.
Reasonable network access policies for the entities under attack plus flow telemetry collection/analysis, S/RTBH, and/or flowspec are a good start, along with this:
<http://www.merit.edu/mail.archives/nanog/msg03776.html>This business of attempting to use packet captures for everything is the equivalent of your doctor attempting to diagnose the reason you're running a fever by using an electron microscope.
Start with the BCPs, then move to the macroanalytical. Only dip into the microanalytical when required, and even then, do so very selectively.
----------------------------------- Roland Dobbins <rdobbins () arbor net>
Current thread:
- Re: Ransom DDoS attack - need help!, (continued)
- Re: Ransom DDoS attack - need help! Daniel Corbe (Dec 03)
- Re: Ransom DDoS attack - need help! Stephen (Dec 09)
- Re: Ransom DDoS attack - need help! Daniel Corbe (Dec 03)
- RE: Ransom DDoS attack - need help! Darden, Patrick (Dec 03)
- Re: Ransom DDoS attack - need help! John Kristoff (Dec 03)
- Re: Ransom DDoS attack - need help! William Herrin (Dec 03)
- Message not available
- Re: Ransom DDoS attack - need help! Robban (Dec 03)
- Re: Ransom DDoS attack - need help! Lyndon Nerenberg (Dec 03)
- Re: Ransom DDoS attack - need help! Robban (Dec 03)
- Re: Ransom DDoS attack - need help! alvin nanog (Dec 03)
- Re: Ransom DDoS attack - need help! Lyndon Nerenberg (Dec 03)
- Re: Ransom DDoS attack - need help! alvin nanog (Dec 03)
- Re: Ransom DDoS attack - need help! Roland Dobbins (Dec 03)
- Re: Ransom DDoS attack - need help! alvin nanog (Dec 04)
- Re: Ransom DDoS attack - need help! Lyndon Nerenberg (Dec 03)
- Re: Ransom DDoS attack - need help! Roland Dobbins (Dec 08)
- Re: Ransom DDoS attack - need help! alvin nanog (Dec 09)
- Re: Ransom DDoS attack - need help! alvin nanog (Dec 09)
- Re: Ransom DDoS attack - need help! Baldur Norddahl (Dec 09)
- Re: Ransom DDoS attack - need help! Baldur Norddahl (Dec 09)