RE: syn DDoS attack solution

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



R. DuFresne writes:
> There have been and will continue to be some
> rather decently funded companies with some fairly decent pipes wiped
> out
> of business or their internet presence closed up due to some of these
> kinds of attacks over extended periods of time.  Goverments across the
> globe have had internet services disrupted for extended periods.
> Microsoft has had to relocate servers to new net/ip addresses to divert
> the flow from such attacks and stay somewhat online...
> 

I won't even tell you what we ended up having to do to get the first large,
commercial DDoS targets back online (Stacheldraht, anyone). The great thing
about DoS attacks is that they tend to be self-propagating. In order to get
them to go away, you generally end up doing things that kills legitimate
connections. Just a casualty of war. Either that or you ride them out.
Invariably, you have to go upstream to get help in stopping them if they are
worth noticing.

Ric




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux