2 ms·
DDoS mitigation is already a mostly solved problem; IDMS/TMS and RTBH are things. Many networks don't install them though, and when they do they often only get
by trelliscoded 10y ago
DDoS mitigation is already a mostly solved problem; IDMS/TMS and RTBH are things. Many networks don't install them though, and when they do they often only get tested once an attack starts. For obvious reasons, many network operators are highly reluctant to hose down production services with test attacks.
Adding crypto isn't going to help in the case where someone's hosing you down with reflected UDP traffic, as the packets are still going to transit your ingress link and clog it up for production requests. Sure, you can force the use of DTLS, but your load balancers are just going to go "well this is bogus traffic" and throw it away, but by then it's too late since it's already in your network.
Mandating egress filtering for traffic isn't going to help that much either, because then a botnet is just going to stop spoofing traffic. This makes it easier to mitigate it from the target's perspective, but with a large enough set of transmitters the target will still see an impact.
The bottom line is that if you want to allow connections from the entire Internet, then every lightbulb, refrigerator, and lawn sprinkler with a wifi chip is eligible to connect to you. Unless there's an effort to create international policies to stop vendors from shipping exploitable firmware for these things, this problem is just going to keep getting worse for those of us who can't afford good DDOS protection.