3 ms·
That's nice but what do start-ups and other less famous organizations do? Any competitor can buy a 30+ gbps attack for a few dollars. http://hackforums.net/fo
by codexon 13y ago
That's nice but what do start-ups and other less famous organizations do?
Any competitor can buy a 30+ gbps attack for a few dollars.
http://hackforums.net/forumdisplay.php?fid=232 http://hackforums.net/forumdisplay.php?fid=232
And it costs $2000/month just for 20 gbps of protection.
https://www.staminus.net/ddos-protection https://www.staminus.net/ddos-protection
https://ordering.blacklotus.net/cart.php?pid=10 https://ordering.blacklotus.net/cart.php?pid=10
DDoS attacks are going to get larger and more frequent.
- jamesaguilar 13y agoI wager it's pretty rare for the following conditions to exist simultaneously: - Small enough that $2k a month is a serious spend. - Big enough to draw the attention of someone who cares to DDoS you. - Important enough to one's customers that a few hours of downtime is a serious issue. If you somehow cause all three to exist at once, either you're going out of your way to piss off the wrong people, or you're not charging enough. (Also, there's always the option to roll your own DDoS protection. It's complicated, but not super complicated, at least for a 90% solution. If I'm not mistaken, it basically involves detecting anomalous traffic and telling upstream routers that you don't exist for the source IP generating that traffic. Someone who knows more about it might be able to fill in some details.)
- codexon 13y ago$2k is just the beginning. If you looked at the forum I just posted, attacks can go up to 60 gbps and still only cost a couple of dollars. This can easily cost as much as a full time employee, and many large sites can be run by 1-2 people. Having to spend 33% more just to stay online is not negligible. You can't just roll your own DDoS protection. If you do this you are looking at rolling your own data centers. Once an attack gets bigger than the port at one of your standard hosts, your host is going to null route you and even kick you off if it happens too often. You are going to be hard pressed to find a host that is willing to broadcast your /24, let alone getting a /24 with this IP shortage if you were going to do your own cloudflare. "If I'm not mistaken, it basically involves detecting anomalous traffic and telling upstream routers that you don't exist for the source IP generating that traffic." This is called null routing. It involves telling your upstream that the IP can't be routed to. This blocks ALL traffic to that IP so your port doesn't get maxed. Large transit providers are going to charge you an arm and a leg to give you an API to insert ACLs because routers have a limited number of rules.
- jlgaddis 13y ago> Large transit providers are going to charge you an arm and a leg to give you an API to insert ACLs because routers have a limited number of rules. It's been my experience that pretty much every transit provider supports this (and at no extra cost). All of my transit providers do. I offer RTBH'ing (by tagging /32s with a specific community) to my customers because I can propagate those to my upstreams in order stop them from sending the traffic to me. Those providers would rather drop 10 Gbps of DDoS traffic at the edge than to worry about an extra entry in routing table.
- codexon 13y agoHe is talking about ACLs, not RTBH.
- sudomal 13y agoA lot of deceptively large websites are barely holding on due to the collapse of the ad industry in 2008... never mind them being able to employ people. An attack is the sort of milestone that would encourage them to give up.
- jlgaddis 13y ago> If I'm not mistaken, it basically involves detecting anomalous traffic and telling upstream routers that you don't exist for the source IP generating that traffic. You're thinking of real-time blackholing (RTBH). "Source-based" blackholing is not an option during most DDoS attacks (spoofed IP addresses) so destination-based blackholing (what everyone refers to when they're talking about RTBH'ing) is your only option. By employing RTBH'ing, you effectively DDoS yourself. Say, for example, that you have a 5 Gbps pipe and an attacker is sending 10 Gbps of traffic to your web server with IP address 203.0.113.42. That level of traffic will saturate your network connection completely, making it completely unusable. Your only choice is to blackhole your web servers' IP address upstream by having your ISP(s) drop traffic destined to 203.0.113.42. At that point, your web server is unreachable by anyone and you've had to DDoS yourself, in effect, in order to be able to use your network connection again. And if they spread their DDoS across all of your IP address space? You'll be able to use your network connection again when the attackers decide to stop. That's hardly rolling your own "DDoS protection".
- abcd_f 13y agoHere's what I don't understand about DDoS mitigation. Say, they targeted x.x.x.x IP and it get RTBH'd, so the DDoS traffic is effectively stopped closer to its origins. Then, in order to bring my service back up, I move to another IP (or I adjust the load-balancing mechanism not to use the original IP). The part I don't understand is why wouldn't DDoS controller simply redirect its attack to another IP? This is surely not that hard to do, and so we are back to where we started and this cycle can in theory continue forever. Also, it follows from the above that the only way to dismantle DDoS attacks is to do traffic fingerprinting, detect malicious requests and then, ideally, have respective ISPs kick originating IPs off the Internet. Does anyone know which providers/services do this and how much it costs?
- codexon 13y agoAttackers will switch to attacking an IP that isn't null routed. You could theoretically keep changing your DNS entries. But many ISPs cache entries for a day instead of whatever your TTL is, so you get customers locked out. Source verification is called BCP38, and as for the cost, this standard was published 13 years ago, and the majority of networks haven't implemented it.
- lobotryas 13y agoHire a really good SysAdmin.
- eksith 13y agoEven a really, really good SysAdmin can't work around what's currently possible with network technology. You really can't serve beyond your network saturation point no matter how much "tweaking" you do. That's gonna cost infrastructure you may not have (and/or cost far more than you can afford).
- smartwater 13y agoYou'd be lucky to get 1/50th of the advertised Gbps. Hackforums is where script kiddies go. It's just a bunch of unemployed kids trying to show off with software/code that they didn't make themselves, but they will sure as hell try to convince you they did.