3 ms·
In a DNS-amplified DDoS attack, target (CF for example) would be on the receiving end (right-hand side of [1]), and blocking, while necessary, would not be terr
by kees99 7y ago
In a DNS-amplified DDoS attack, target (CF for example) would be on the receiving end (right-hand side of [1]), and blocking, while necessary, would not be terribly efficient there.
On the other hand, deprecating "ANY" requests as standard, once percolated into BIND and other resolvers, would cut the attack[2] on the amplification stage (middle of the picture of [1]).
[1] https://www.cloudflare.com/img/learning/ddos/dns-amplification-ddos-attack/dns-amplification-attack-1.png https://www.cloudflare.com/img/learning/ddos/dns-amplificati...
[2] or at least significantly decrease choice and depth of large amplification factor requests available to the attacker.