3 ms·
I'm also appalled by why they even need to recode a radix tree themselves to filter out a DDOS, considering the many options available without reimplementing th
by bahhh 8y ago
I'm also appalled by why they even need to recode a radix tree themselves to filter out a DDOS, considering the many options available without reimplementing the wheel.
any serious hoster filter out ddos with a router. routers are basically build to test IP against subnets, so they can basically run each IP address against a million of hardware subnet testers all running in parallel and decide what to do depending on the result.
And if you don't have a router, any OS worth its salt already have a radix tree implementation for its routing table. The only thing you need to turn a Linux routing table into a ddos filter is to enable reverse path filtering and then add blackhole routes with iproute2.