Carpet bombing, what's it look like now
Mike Hammett via NANOG <[email protected]> Fri, 31 Jul 2026 18:50:51 +0000 (UTC)
| Newsgroups | gmane.org.operators.nanog |
|---|---|
| Message-ID | <[email protected]> |
The single destination case is easy enough. You RTBH the /32, renumber the customer, and move on. Carpet bombing takes that option away, since there's nowhere to move anyone to and nothing crosses a per-host threshold to trigger on in the first place. I'm curious what it actually looks like for those of you dealing with it regularly. Everything I've read says ports and packet sizes are randomized wide enough now that signature matching isn't worth much, though I'd rather hear that from someone watching it happen than from a vendor report. Does destination prefix plus protocol and port still get you something tight enough to act on, and if so, how many rules do you end up carrying mid-attack? Somewhat related, does packet length matching actually work on your hardware? I've been reminded lately that documented and functional aren't always the same thing. What are you feeding detection with, and does it keep up? sFlow, IPFIX, port mirror, something else. With attacks routinely over inside a couple of minutes I'm not convinced sampled telemetry is fast enough to matter, and I'd like to know whether people are installing rules after the thing already ended. If you're sampling, has any ratio worked well enough that the low per-host rates of a carpet bomb still trip an aggregate threshold in time to act? The other half of this is lifecycle. How long do you leave rules installed, and what tells you it's safe to pull them? Pull too early and you re-detect the same attack. Leave them in and you're carrying stale state indefinitely. Once you've got a signature, what do you actually do with it? Drop outright, rate limit, or hand it to a scrubber? I'd expect that to track how confident you are that nothing legitimate matches, but I'm curious where people really draw those lines. Our bar is customers not noticing rather than stopping every packet, and those turn out to be different targets. What's everyone doing for v6? Flowspec support looks thin enough there that a carpet bomb against v6 space puts you back to blackholing hosts one at a time. Separate question: is anyone pairing FastNetMon or similar detection with a self-hosted scrubber like VPP or Gatekeeper, rather than handing the traffic off to a provider? Interested in the outbound direction as well, catching a compromised customer before the traffic leaves. If you do answer, rough network size helps. Forty rules at 10G and forty rules at 1T aren't the same finding. ----- Mike Hammett Intelligent Computing Solutions Midwest Internet Exchange The Brothers WISP _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/[email protected]/message/QVUNFLT26C54FTPK2DNAF5RKFZLTE3H7/