HN user

ttimrawi

1 karma
Posts0
Comments2
View on HN
No posts found.

jacquesm,

Not a single provider in the world can handle this kind of attack peacefully without service interruption except China Telecom and China Union.

Your calculations can't be more off about 50K bots, our counts showed more than 100K we couldn't count after that due to limitation in software.

My business has been dealing with DDOS attacks since 2002 we pretty much saw the brunt of every kind of new attack that came online. The only thing that can be compared with magnitude to this is the DNS Amplification attack, but that was limited in it's impact considering the source of the attack was diverse not from one geo area.

Considering the fact I've seen this attack first hand. I can tell you a couple of things about it's strength. It's very flexible one minute they are sending packet size 1500 bytes udp, the other they are sending 48 bytes syn tcp 80. However, filtering them with a Firewall is not hard at all since they do have packet patterns you can detect, but even if you can find a firewall and have it on the edge of your network traffic is STILL reaching your network and if you can handle 50Gbps of traffic all coming from a couple of different ASn than "wow".