3 ms·
While I agree with other commenters that 100/hour doesn't rise to the level of "attack," I'm also curious, because with a forged peer address these are certainl
by ericbarrett 3y ago
While I agree with other commenters that 100/hour doesn't rise to the level of "attack," I'm also curious, because with a forged peer address these are certainly not probes—the true sender would not get a response either way. Unless, that is, the spoofed IPs are also controlled by the attacker. I wonder if you'd find any patterns (net range, ASN, geographical, residential, etc.) in an analysis.
It could also be that your server—no doubt along with millions of others—is simply being used as a bouncer to shield the origin of a DDoS attack. Typically attackers want "amplification" (send a tiny packet with a spoofed source address, get a large response) but if their pipe is big enough they may be content with a level of indirection.