[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Reaching out to Sony NOC, resolving DDoS Issues - Need POC
Peace,
On Tue, Jan 28, 2020, 4:32 AM Damian Menscher <damian at google.com> wrote:
> On Mon, Jan 27, 2020 at 5:10 PM Töma Gavrichenkov <ximaera at gmail.com>
> wrote:
>
>> If this endpoint doesn't connect to anything outside of their network,
>> then yes.
>> If it does though, the design of the filter might become more complicated.
>>
>
> Not really... just requires sorting by volume. Turns out most legitimate
> hosts don't send high-volume syn packets. ;)
>
This is a good *detection* technique, but you cannot filter by volume in
transit if the set of destinations is large (and random) enough, and you
don't have a time machine. Not sure if this is the case but might as well
be.
As for the detection of the real source, everything is technically possible
but you need certain bargaining power which a medium-sized (at best) VPN
service probably doesn't have.
--
Töma
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20200128/8ba59a75/attachment.html>
- References:
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: kmedcalf at dessus.com (Keith Medcalf)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: mlm at pixelgate.net (Mark Milhollan)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: admin at octolus.net (Octolus Development)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: damian at google.com (Damian Menscher)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: admin at octolus.net (Octolus Development)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: Roland.Dobbins at netscout.com (Dobbins, Roland)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: nanog at ics-il.net (Mike Hammett)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: ben at 6by7.net (Ben Cannon)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: nanog at ics-il.net (Mike Hammett)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: damian at google.com (Damian Menscher)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: ximaera at gmail.com (Töma Gavrichenkov)
- Reaching out to Sony NOC, resolving DDoS Issues - Need POC
- From: damian at google.com (Damian Menscher)