3 ms·
When I worked at an ISP years back, if we had a DDOS attack against a customer the way we handled that was to drop all traffic incoming towards that customer's
by d1zzy 6y ago
When I worked at an ISP years back, if we had a DDOS attack against a customer the way we handled that was to drop all traffic incoming towards that customer's IP at our external peer level (meaning the bigger ISP we were getting most of the external Internet from). That was necessary so all of that DDOS traffic wasn't eating from the bandwidth available to all other customers that weren't being DDOS-ed. But it also meant that the DDOS-ed customer was losing all Internet access (which wasn't really much of a change considering that they were receiving a DDOS that filled all their allocated bandwidth).
Repeat customers that would get DDOS too many times (cybercafes would fall into that category often) would have to either pay more to cover for the cost of the network engineers dealing with the DDOS or get the boot.
From what I remember it's quite similar with many service providers, including hosting providers. Their TOS will allow them discretion to stop providing services to anyone that may negatively impact their business, it's not like there's any law that forces them to provide service to a customer.