4 ms·
> Your defense mechanism is actually the exact thing > described as protection against a simple DDOS attack. With > a REAL ddos attack [..] I'm not entirely
by bArray 7y ago
> Your defense mechanism is actually the exact thing
> described as protection against a simple DDOS attack. With
> a REAL ddos attack [..]
I'm not entirely sure what is really classified as a "simple" vs "real" DDoS attack.
> With a REAL ddos attack you will get so many incoming
> traffic that your bandwidth is saturated before any
> software will come in effect.
I specifically said: "as long as the network bandwidth itself can hold out". If the network is saturated, it's saturated - it's game over, for anybody. But you'll find that most services will die way before this limit is reached. On a WordPress site for example you'll usually find the database will give out long before the bandwidth is saturated.
Even with legitimate users coming through some great filter like CloudFlare, it doesn't prevent a hug-of-death if you don't have some "smart" application level handling of high numbers of users. Like Linux OOM, when you hit your limits, the only choice left is to try and quickly and intelligently start killing without affecting the well behaved.