4 ms·
The big boys seem to be a little reluctant to publish information on their DDoS strategies. (If anyone has information that says otherwise, it's much appreciate
by mpk 18y ago
The big boys seem to be a little reluctant to publish information on their DDoS strategies. (If anyone has information that says otherwise, it's much appreciated).
I spent some time googling around and in case anyone's interested, these links seem to cover most of the mitigation patterns.
A slideshow covering common mitigation techniques,
http://www.slideshare.net/intruguard/10-ddos-mitigation-techniques-presentation http://www.slideshare.net/intruguard/10-ddos-mitigation-tech...
A Cisco whitepaper (which, as usual, has en emphasis on Cisco kit and a long URL),
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5879/ps6264/ps5888/prod_white_paper0900aecd8011e927_ns615_Networking_Solutions_White_Paper.html http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5879/ps...
A fairly comprehensive PDF document - A Survey of Active and Passive Defence Mechanisms against DDoS Attacks
http://www.fbi.cqu.edu.au/FCWViewer/getFile.do?id=17921 http://www.fbi.cqu.edu.au/FCWViewer/getFile.do?id=17921
- lacker 18y agoThe big boys seem to be a little reluctant to publish information on their DDoS strategies. Makes sense, the bad guys are just as likely (if not more) to read up about them.
- tptacek 18y agoI don't know how secret this stuff is; I think if you poke around NANOG, you'll find a lot of material. If there's something that makes DDoS mitigation mysterious, it's how ad hoc all this stuff is. What I've had firsthand experience with is: * Tier-1's profile all their traffic, either directly or with flow export, and will get alerts if they see spikes to certain netblocks, or spikes to specific /32s with specific characteristics. * Inside a Tier-1, the third-tier support people usually have additional monitoring they can enable for customers if an incident has been escalated to them. They get hundreds of these calls a week. * A lot of Tier-1's can quickly reroute traffic to a specific /32 to run through special-purpose filtering setups, which might be a DDoS box like a Cisco/Riverhead, or an IPS like TippingPoint, or even just a Cat with lots of TCAM space set aside for filtering. * A lot of Tier-1's --- maybe all at this point --- have some mechanism set up to share signatures of attacks so they can push filtering further upstream. When I watched that stuff happening, the sense I got of it was that this was really reserved for things like global botnet C&C. What I'd add to the discussion on products is, most of what's built to combat DDoS is really only useful if you sell transit. If you're a Fortune 500, I know there are ISPs where you can get Cisco or Arbor gear deployed on the head end specially for you. But that's a Fortune 500, not 37 Signals.