nanog mailing list archives

Re: DDOS solution recommendation


From: "Roland Dobbins" <rdobbins () arbor net>
Date: Sun, 11 Jan 2015 16:24:48 +0700


On 11 Jan 2015, at 13:30, Ammar Zuberi wrote:

I've done a lot of research into how these attacks actually work and most of them are done by kids who don't really know what they're doing.

The really sad part is that in a huge of the cases we see, the attacks are hugely disproportionate - so many servers/services/applications/networks are so brittle and fragile and non-scalable that only a fraction of the pps/bps/cps/qps generated by the attackers would take them down, anyways.

Even worse, the attackers who don't know what they're doing routinely achieve their goals, anyways, due to the above plus the unpreparedness of the defenders. I've only run across a handful of organizations which proactively took appropriate defensive measures; most only do so in the aftermath of a successful attack.

It's easy to be an Internet supervillain.

-----------------------------------
Roland Dobbins <rdobbins () arbor net>


Current thread: