Carpet bombing, what's it look like now

Mike Hammett via NANOG <[email protected]> Fri, 31 Jul 2026 18:50:51 +0000 (UTC)
Newsgroups gmane.org.operators.nanog
Message-ID <[email protected]>
The single destination case is easy enough. You RTBH the /32, renumber
the customer, and move on. Carpet bombing takes that option away, since
there's nowhere to move anyone to and nothing crosses a per-host
threshold to trigger on in the first place.



I'm curious what it actually looks like for those of you dealing with
it regularly. Everything I've read says ports and packet sizes are
randomized wide enough now that signature matching isn't worth much,
though I'd rather hear that from someone watching it happen than from a
vendor report. Does destination prefix plus protocol and port still get
you something tight enough to act on, and if so, how many rules do you
end up carrying mid-attack? Somewhat related, does packet length
matching actually work on your hardware? I've been reminded lately that
documented and functional aren't always the same thing.



What are you feeding detection with, and does it keep up? sFlow, IPFIX,
port mirror, something else. With attacks routinely over inside a
couple of minutes I'm not convinced sampled telemetry is fast enough to
matter, and I'd like to know whether people are installing rules after
the thing already ended. If you're sampling, has any ratio worked well
enough that the low per-host rates of a carpet bomb still trip an
aggregate threshold in time to act?



The other half of this is lifecycle. How long do you leave rules
installed, and what tells you it's safe to pull them? Pull too early
and you re-detect the same attack. Leave them in and you're carrying
stale state indefinitely.



Once you've got a signature, what do you actually do with it? Drop
outright, rate limit, or hand it to a scrubber? I'd expect that to
track how confident you are that nothing legitimate matches, but I'm
curious where people really draw those lines. Our bar is customers not
noticing rather than stopping every packet, and those turn out to be
different targets.



What's everyone doing for v6? Flowspec support looks thin enough there
that a carpet bomb against v6 space puts you back to blackholing hosts
one at a time.



Separate question: is anyone pairing FastNetMon or similar detection
with a self-hosted scrubber like VPP or Gatekeeper, rather than handing
the traffic off to a provider? Interested in the outbound direction as
well, catching a compromised customer before the traffic leaves.



If you do answer, rough network size helps. Forty rules at 10G and
forty rules at 1T aren't the same finding.







-----
Mike Hammett
Intelligent Computing Solutions


Midwest Internet Exchange


The Brothers WISP
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/[email protected]/message/QVUNFLT26C54FTPK2DNAF5RKFZLTE3H7/