Re: Carpet bombing, what's it look like now

Saku Ytti via NANOG <[email protected]> Sat, 1 Aug 2026 09:17:36 +0300
Newsgroups gmane.org.operators.nanog
Message-ID <CAAeewD-6UR+u-EPhZ4SE+zNSde-+Pu+SKRV-XQ8ESzNnmuckFg@mail.gmail.com>
On Fri, 31 Jul 2026 at 21:51, Mike Hammett via NANOG
<[email protected]> wrote:

> vendor report. Does destination prefix plus protocol and port still get
> you something tight enough to act on, and if so, how many rules do you
> end up carrying mid-attack? Somewhat related, does packet length
> matching actually work on your hardware? I've been reminded lately that
> documented and functional aren't always the same thing.

Packet size matching in my experience tends to work on most gear,
particularly on gear you'd use on edge.
More so, flexible packet matching is increasingly available that
allows highly specific pattern matching,
if any is available.

> What are you feeding detection with, and does it keep up? sFlow, IPFIX,

IPFIX. But sampling rate is making things tricky, as very short term
attacks are a thing.

> Once you've got a signature, what do you actually do with it? Drop
> outright, rate limit, or hand it to a scrubber? I'd expect that to

Customers who pay for scrubbers get scrubbers. If there is a specific
target, blackholes or ACL. If wide carpet,
QoS downgrade, no explicit rate-limit, transport the attack if we have
excess capacity to do so.

> What's everyone doing for v6? Flowspec support looks thin enough there
> that a carpet bomb against v6 space puts you back to blackholing hosts
> one at a time.

Same as v4.

-- 
  ++ytti
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/[email protected]/message/2YP2Q5EKJDBCHGM6UNELFR7DES2U4L7Y/