6 ms·
I didn't downvote you but I can see why they did. The way you act is similar to someone running a contest to disprove Turing's proof on the halting problem. If
by codexon 12y ago
I didn't downvote you but I can see why they did. The way you act is similar to someone running a contest to disprove Turing's proof on the halting problem.
If your bandwidth is being filled from the other end, it doesn't matter how sophisticated the filter is at your server. Even if it is theoretically perfect and able to tell which packets came from real requests with 100% accuracy, it will not solve the problem. This limitation also applies to hardware firewalls.
Many smart people have already tried to solve the DDoS problem and they all came to the same conclusion. Either everyone does BCP38, which is never going to happen, or you buy more bandwidth than your attacker can throw at you.
To suggest that all we have to do to solve this is dangle chump change for some random coder to solve it is rather silly especially when companies like Cloudflare and Prolexic have bet their entire futures on DDoS not being fixed any time soon.
As someone who deals with DDoS attacks every month it is rather obvious that you don't have a very good idea of how ddos attacks work when everything in the list you copied off a random website except for SYN could be classified as attacks that overflow your bandwidth. UDP fragments and Chargen are also bandwidth attacks.
- joshuak 12y agoI understand your position, and I don't want to be offensive. I simply want to be clear. The X-Prize is intended precisely for this type of industry stagnation, and has been very successful at that goal so far. Winners solve unbelievable problems in unbelievable ways. I am, if not an expert, nearly so, and I can say that my first thought is not better filtration. As you rightly point out that is a very hard problem, technically impossible too if you limit the framing of the problem to only information available to the server and consider each event in isolation. I am a little surprised that you as a self professed expert keep harping on the futility of better serverside filtration when your very argument is that it isn't a good approach. Why are you assuming that others would choose a poor approach when you would not? For example my first thoughts go to ideas like: a home firewall auto configuration / lockdown tool and associated marketing campaign; inexpensive home network security hardware; better anti bot software; a police botnet; browser and os patch sets; political campaigns to change regulatory requirements; graphic design, video and other media to improve understanding and provide easy to implement solutions, economic/business models that naturally incentivise users and/or device vendor to prefer better security features on devices. In the end perhaps it would be none of these things are perhaps it would be some particularly spectacular bit of server filter coding. The point of prize systems like the X-Prize is to efficiently solve hard problems. It is not to solve it in any particular way. Is there no better algorithm to recommend movies? No there isn't, until you consider human factors (The Netflix Prize). Is human space travel truly only the domain of nation states? Yes it is, until the Ansari X-Prize. Before these prizes were won, their solutions were impossible, afterwards they are simply solved problems. -- P.S. In addition to your mistaken impression of my inexperience in the filed you are also mistaken that the information I posted is "off a random website". The information is from Akamai's State of the Internet site and represents Akamai's "real-time 24-hour global attack data: sources, targets, and types of attacks". It is linked to directly from Prolexic's home page. Though, I'm sure as an expert you knew that.
- killerstorm 12y ago> The X-Prize is intended precisely for this type of industry stagnation No. Take a look Ansari X-Prize, the first of this kind. The theoretic foundations for spaceflight were laid out about a century ago, the first flight took place in 1961. So this is something which is very well understood. The prize was, basically, for tweaking the components to make it cheaper. But you're asking somebody to invent a new method, without providing a theoretical foundation for it to work in. So this would be like asking to invent a teleporter or faster-than-light travel. Besides that, other x-prizes were formulated as a contained experiments. E.g. demonstrate that your spacecraft can fly, or provide a program which offers better recommendations. But what you describe is not an experiment. You actually want participants to go an change how the Internet works. This isn't contained. So you're being downvoted for being extremely naive. You seem to believe that a kickstarter campaign and a github repo can solve any problem.
- codexon 12y agoEverything you've suggested requires all networks to cooperate/spend extra time and money, or that no one makes an exploitable protocol in the future (as likely as humans never making mistakes). If you can already get all networks to cooperate/spend extra time and money, then you can make them do BCP38 which would be a more complete solution. > In addition to your mistaken impression of my inexperience in the filed you are also mistaken that the information I posted is "off a random website". The information is from Akamai's State of the Internet site and represents Akamai's "real-time 24-hour global attack data: sources, targets, and types of attacks". It is linked to directly from Prolexic's home page. Though, I'm sure as an expert you knew that. And all of this doesn't disprove anything I said. That website is a marketing piece made for laymen such as yourself. The fact that you are categorizing those attack vectors as seperate problems instead of being in the same class proves what I claim.