4 ms·
When you get network level ddos on digital ocean, they can't save you. This rules out small clouds for us. So, we use GCP Azure AWS exclusively because of the
by InGodsName 8y ago
When you get network level ddos on digital ocean, they can't save you.
This rules out small clouds for us.
So, we use GCP Azure AWS exclusively because of their ability to defy network level ddos.
- NicoJuicy 8y agoPut cloudflare in front then, you can use it with Digital Ocean. So you're saved then.
- brazzledazzle 8y agoOr Akamai’s mitigation services if you can afford it. I’m curious how big that value proposition is these days. I wonder how much DDoS it takes before a cloud provider starts dropping a customer’s packets now. Do they even bother anymore?
- dpflan 8y agoThis is an interesting point. Did you originally use a non network-level-ddos-defying CSP and then switch? I am curious when this became a variable to consider as an item to explicitly pay more for (e.g. going from AWS Shield standard to advanced or picking big-3 CSP with higher price because of DDOS-protection) / when the inflection point in the business where DDOS-protection is now a serious consideration due to financial impact/user impact occurred (if possible to point to).
- InGodsName 8y agoYes, we used baremetal and digital ocean before that. Why? Mostly because of cost and it seemed simple than building out stuff on cloud services. Every Friday night, our services got ddosed by our competitors. Provider would nullroute our IPs and our service goes down We struggled with it a lot since we were not big enough to afford a premium ddos solution. Once we realized that big cloud like aws, gcp do not suffer from this, we had to make a switch.
- deleted 8y ago[deleted]
- altmind 8y agoHow do you manage to mitigate a DDOS on a public cloud? When you say GCP, Azure and AWS have the capacity to defy the ddos, what capacity are you reffering to? Are you talking about actually scaling and serving the bogus requests? Or capacity to have enoough bandwith and firewall power to fend it off?
- scurvy 8y agoThe clouds don't do any filtering or mitigation for free. They just have enough bandwidth to pass the attack through to your servers and services. You're just moving the bottleneck here, as now you need to use a cloud DDoS mitigator like Silverline, Cloudflare, prolexic. You probably would have been better off using a cloud mitigator from the start. Their pricing is competitive when you factor in all of the costs.
- deleted 8y ago[deleted]
- InGodsName 8y agoThey do filter the malacious traffic if you use their loadbalancer. Loadbalancer is shared across the user accounts, so amazon has to stop the ddos. They've very effective network level ddos detector/filtering
- aynsof 8y agoI can only talk for AWS, not GCP or Azure, but there are services that can help mitigate DDOS attacks: Shield (https://aws.amazon.com/shield/ https://aws.amazon.com/shield/) is AWS's DDOS protection service. It's free and is basic protection against L3/4 attacks. Shield Advanced (same URL as above) is a big step up in price, but gives you access to 'improved protection' and a global response team. Cloudfront (https://aws.amazon.com/cloudfront https://aws.amazon.com/cloudfront) is a CDN with global edge locations. WAF (https://aws.amazon.com/waf https://aws.amazon.com/waf) is AWS's web application firewall service. It's less about DDOS and more about specific application attacks, but is part of the whole solution. For more detail, you can have a look at AWS's DDOS whitepaper: https://d0.awsstatic.com/whitepapers/Security/DDoS_White_Paper.pdf https://d0.awsstatic.com/whitepapers/Security/DDoS_White_Pap...