3 ms·
What alternative would you propose? With a virtual machine an attack on one instance can effect everyone on the same machine. Also actually blocking the attack
by devicenull 13y ago
What alternative would you propose? With a virtual machine an attack on one instance can effect everyone on the same machine. Also actually blocking the attack is very expensive.
- toast0 13y agoIt's worse than that; a DDoS can also overwhelm the networking infrastructure, affecting other machines on the same switches, or in the same facility (depending on the magnitude of the attack, and the capacity of the networking). Null routing does a good job of mitigating impact to other servers, but obviously causes problems. If there's enough capacity, filtering at the border would probably work. I think most of the attacks these days are DNS reflection (because it's easy and effective), so if the border routers could be configured to drop incoming udp from port 53 to the IP under attack, that would get you most of the way there (just make sure the server under attack doesn't need to get port 53 replies from the internet). That sounds simple, but it has three big problems: a) You need a lot of spare input bandwidth. b) You need to be able to filter on border routers. c) You need to be able to safely change the filters on the border routers.
- devicenull 13y agoDNS reflection, chargen reflection, and SNMP reflection. You can block them all fairly easily, but you still need enough upstream bandwidth to deal with them.
- bolder88 13y agoMy alternative would be firstly to legislate that any network can only send packets that have a source address owned by them. This would drastically cut down source address spoofing, which is the worst type of DDoS to try to cope with. Secondly I'd setup a far better method of reporting and blocking traffic up the chain.