3 ms·
That may be the intention [2], but it isn't the effect. Prioritizing EBS as was suggested above is prioritizing by server. But let's say that there was some r
by tc 17y ago
That may be the intention [2], but it isn't the effect.
Prioritizing EBS as was suggested above is prioritizing by server. But let's say that there was some reasonable way to priority-queue EBS-like traffic regardless of the provider (there really isn't [1]). The DDOS attacker would then certainly use this priority channel, which would magnify the effect of their attack ten fold.
[1] Let me explain this in greater detail:
The best way to do QoS is to have end-devices tag their own IP traffic with the appropriate DSCP bits. After all, only the end devices can be really certain about the class of some packet. In your network, you then establish policies for how the various classes of packets should be prioritized and limited.
This works great inside a private network (like AWS, or an ISP). For one thing, you can establish clear standards on how different types of packets should be marked, and you can order them appropriately. You can trust the classifications to the same degree you trust your own systems and (potentially) your customers (depending on checks you do at your service edge). Also, your network gear can prioritize efficiently because only one bit field needs to be checked to determine priority.
Once you step outside of a private network, this all breaks down. First off, most carriers strip DSCP bits at the network edge, so these don't propagate end to end on the internet. Even if you receive a DSCP tag from the outside though, why should you trust it, and how could you trust that it is tagged according to your policies? If Youtube sets all their traffic network control priority, and you trust it, your network would grind to a halt under load. More problematically, though, how can you meaningfully (and generically) differentiate Youtube packets from DDOS packets?
I don't expect you to have answers to these questions; they are hard problems that the best internet engineers in the world haven't solved yet. But this is the background on why an enforced government Net Neutrality mandate is going to throw all QoS policies into question.
[2] And trust me, I've very sympathetic to that intention. On net, Net Neutrality would be a win for my business. But it is still bad policy. What makes people so sure we should give politicians like GWB or Pelosi final say about network engineering [3]...
[3] Once the interest groups realize that centralized national network engineering policy is up for grabs in Washington every 2 years, have you thought about all the unpleasant directions this could go?
- tsuraan 17y agoTo be honest, I'm not actually sure what QOS even has to do with the initial post in this thread; wouldn't a dedicated private ethernet network between the ECC machines and the EBS machines (assuming it's possible within Amazon's network structure) have worked, assuming that their switches are configured to only allow communication between ECC and EBS (forbid ECC - ECC traffic)? Your commentary about how this would deprioritize other traffic wouldn't then be quite right; it would be a dedicated network, with no cost to any external sites. It would obviously give EBS an "unfair" advantage over anybody who wants to provide an ECC block storage solution to compete with EBS, but honestly, is that a concern? Nobody's demanding that all internet hosts (end-user included) have the same bandwidth to all other hosts. It's just artificial crippling of services that are bad, not some things having advantages over others. QoS on the general web doesn't seem likely, as you point out. Prioritization based on which services can afford to pay off all the nation's ISPs seems like a really bad idea though. As a service provider, I don't want to have to pay kickbacks to every ISP in the country (world?) to ensure that no unfortunate accidents befall my traffic. Much more personally, though, as a human, I'm sick of being sold as a product. I don't watch commercial TV because I'm not a product to be sold to advertisers. Similarly, I'm not a product for Comcast to sell to google; that's how they see me, but it's not how I see myself. And, I get pissed off when people see me that way :)
- tc 17y agowouldn't a dedicated private ethernet network With appropriate capacity, a VLAN/QoS configuration is functionally identical to having physically separated networks. On an abstract level, if you object to provider prioritization, you should probably object to them running separate physical networks for their own services. As to your point about feeling screwed by the (mostly theoretical) possibility of intentional service degradation, I sympathize. I'll point out though that 1) I'm quite certain this isn't terribly prevalent in the US, 2) in most cases where people think this is happening it is the result of simple under-capacity or generally bad network design or management, and 3) the correct answer to this general issue is to enable provider competition, not to impose ham-handed mandates.
- tsuraan 17y ago