4 ms·
You aren't going to make ddos attacks go away by offering prizes for a miracle software solution. It amazes me that there are so many programmers here who don't
by codexon 12y ago
You aren't going to make ddos attacks go away by offering prizes for a miracle software solution. It amazes me that there are so many programmers here who don't understand this basic principal. I think the only way we can get people to understand the situation is with an analogy.
Let's say your pipe can receive 1 Liter per second of water. There are some impurities that you can filter through your faucet, this is analogous to the software firewall. However what happens when someone starts piping 99 L/s of sludge through the other end? No matter how sophisticated the filter you have on your faucet, the water you will get out of it is going to slow to a trickle.
Now I can already hear you asking, why does the Internet allow people to send whatever sludge they want? And the answer is because that's the way the internet is made. There has been a push to stop spoofing called BCP38, but this requires EVERYONE to do extra work and spend extra money which is why relatively little progress has been made since it was released 15 years ago, and is likely to never succeed.
If it was as easy as creating a piece of software to deal with, large businesses like Prolexic wouldn't be banking their future on a problem that would be so easily solved.
- joshuak 12y agoI think there are plenty of people, myself included, who understand how DDoS attacks work. Do you know how X-Prizes work? Hit: Did I say anything about software? [edit: It's odd to me that this would get down voted. Is it offensive? Or are downvoters really that opposed to thinking outside of the box? The X-Prize encourages participation from unexpected directions, precisely where innovation is often found. As the parent post demonstrates (almost as if on queue), it's quite common for skilled experts within a field to become overly focused on specific classes of solution. I was careful not to say anything about how the above goals might be achieved.]
- edmccard 12y ago>Did I say anything about software? Well, you did say: "Who'd like to sponsor? Or should I just spin up a GitHub repo for the code and a kickstarter for the prize money?"
- joshuak 12y agoIndeed I did, still no software implication. I was being fairly deliberate about that. What I'm confused about is what the argument is. Is it we shouldn't try to find a solution? I'm sorry if I was unclear that I did not intend to limit the scope of solutions to software, but frankly so what even if I had? In any case the X-Prize proposal seems quite popular so I'd be happy to set it up, help someone else set it up or in general do anything I can to encourage innovative solutions of any kind, but.. ...never tell me the odds.
- v3ss0n 12y agoPlease stop defending yourself , accept what other know what they talking please. You cannot setup a github repo for that.
- codexon 12y agoI didn't downvote you but I can see why they did. The way you act is similar to someone running a contest to disprove Turing's proof on the halting problem. If your bandwidth is being filled from the other end, it doesn't matter how sophisticated the filter is at your server. Even if it is theoretically perfect and able to tell which packets came from real requests with 100% accuracy, it will not solve the problem. This limitation also applies to hardware firewalls. Many smart people have already tried to solve the DDoS problem and they all came to the same conclusion. Either everyone does BCP38, which is never going to happen, or you buy more bandwidth than your attacker can throw at you. To suggest that all we have to do to solve this is dangle chump change for some random coder to solve it is rather silly especially when companies like Cloudflare and Prolexic have bet their entire futures on DDoS not being fixed any time soon. As someone who deals with DDoS attacks every month it is rather obvious that you don't have a very good idea of how ddos attacks work when everything in the list you copied off a random website except for SYN could be classified as attacks that overflow your bandwidth. UDP fragments and Chargen are also bandwidth attacks.
- joshuak 12y agoI understand your position, and I don't want to be offensive. I simply want to be clear. The X-Prize is intended precisely for this type of industry stagnation, and has been very successful at that goal so far. Winners solve unbelievable problems in unbelievable ways. I am, if not an expert, nearly so, and I can say that my first thought is not better filtration. As you rightly point out that is a very hard problem, technically impossible too if you limit the framing of the problem to only information available to the server and consider each event in isolation. I am a little surprised that you as a self professed expert keep harping on the futility of better serverside filtration when your very argument is that it isn't a good approach. Why are you assuming that others would choose a poor approach when you would not? For example my first thoughts go to ideas like: a home firewall auto configuration / lockdown tool and associated marketing campaign; inexpensive home network security hardware; better anti bot software; a police botnet; browser and os patch sets; political campaigns to change regulatory requirements; graphic design, video and other media to improve understanding and provide easy to implement solutions, economic/business models that naturally incentivise users and/or device vendor to prefer better security features on devices. In the end perhaps it would be none of these things are perhaps it would be some particularly spectacular bit of server filter coding. The point of prize systems like the X-Prize is to efficiently solve hard problems. It is not to solve it in any particular way. Is there no better algorithm to recommend movies? No there isn't, until you consider human factors (The Netflix Prize). Is human space travel truly only the domain of nation states? Yes it is, until the Ansari X-Prize. Before these prizes were won, their solutions were impossible, afterwards they are simply solved problems. -- P.S. In addition to your mistaken impression of my inexperience in the filed you are also mistaken that the information I posted is "off a random website". The information is from Akamai's State of the Internet site and represents Akamai's "real-time 24-hour global attack data: sources, targets, and types of attacks". It is linked to directly from Prolexic's home page. Though, I'm sure as an expert you knew that.