5 ms·
Out of curiosity, who pays more -- the attacker or the victim? Purely from a monetary perspective. Edit: never mind, figured it's obvious. Aren't DDoS request
by toaskaquestion 12y ago
Out of curiosity, who pays more -- the attacker or the victim? Purely from a monetary perspective.
Edit: never mind, figured it's obvious.
Aren't DDoS requests pretty much simple GET requests? Is it not possible to determine which requests to serve and which ones to ignore?
- SeoxyS 12y agoThe attackers typically have a botnet at their disposal. The victim has to pay their own costs.
- twunde 12y agoThe requests can vary. Sometimes they are simple GET requests, sometimes they're exploiting a cpu|memory|io-intensive process in the application and sometimes they can be reflected DNS attacks. The problem is separating the legitimate requests from the bad requests. Sure I can see there are 5 Million requests to the main page of the app. But which are from poeple legitimately trying to use the application and which are from the botnet? You can't just do it by IP without running the chance you're going to cause problems for legitimate users. There are ways to mitigate this but it requires being able to analyse current traffic and past traffic quickly, and at scale while having the expertise to set up firewalls and other filtering correctly
- Sanddancer 12y agoThese days, DDoSes are not just lots of GET requests, because, as you said, they're fairly easy to mitigate. These days, the most common attacks are various UDP-based attacks, like NTP reflection [1]. You send a spoofed header to a server that speaks over UDP, and they send a huge amount of traffic to the victim. https://blog.cloudflare.com/understanding-and-mitigating-ntp-based-ddos-attacks/ https://blog.cloudflare.com/understanding-and-mitigating-ntp...
- lucaspiller 12y agoCouldn't something like that be blocked at a firewall level with AWS though, i.e. drop everything except TCP port 80?
- deleted 12y ago[deleted]
- web007 12y agoThere are things like amplification attacks (DNS or NTP) where a small amount of attack traffic generates a huge amount of target traffic. Even if the traffic is symmetric (1 byte to target = 1 byte from attacker) the bad guys tend to have botnets / malware-infected systems so they don't pay the cost of the attack side. If the attackers are just sending GETs you might be able to filter them out, but if they're sending random packets you usually need upstream help to keep them from getting to you to begin with. There are also things like Slowloris that just use up resources vs using bandwidth, those are harder to identify but easier to deal with on a server-by-server basis.