Re: Carpet bombing, what's it look like now
Saku Ytti via NANOG <[email protected]> Sat, 1 Aug 2026 09:17:36 +0300
| Newsgroups | gmane.org.operators.nanog |
|---|---|
| Message-ID | <CAAeewD-6UR+u-EPhZ4SE+zNSde-+Pu+SKRV-XQ8ESzNnmuckFg@mail.gmail.com> |
On Fri, 31 Jul 2026 at 21:51, Mike Hammett via NANOG <[email protected]> wrote: > vendor report. Does destination prefix plus protocol and port still get > you something tight enough to act on, and if so, how many rules do you > end up carrying mid-attack? Somewhat related, does packet length > matching actually work on your hardware? I've been reminded lately that > documented and functional aren't always the same thing. Packet size matching in my experience tends to work on most gear, particularly on gear you'd use on edge. More so, flexible packet matching is increasingly available that allows highly specific pattern matching, if any is available. > What are you feeding detection with, and does it keep up? sFlow, IPFIX, IPFIX. But sampling rate is making things tricky, as very short term attacks are a thing. > Once you've got a signature, what do you actually do with it? Drop > outright, rate limit, or hand it to a scrubber? I'd expect that to Customers who pay for scrubbers get scrubbers. If there is a specific target, blackholes or ACL. If wide carpet, QoS downgrade, no explicit rate-limit, transport the attack if we have excess capacity to do so. > What's everyone doing for v6? Flowspec support looks thin enough there > that a carpet bomb against v6 space puts you back to blackholing hosts > one at a time. Same as v4. -- ++ytti _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/[email protected]/message/2YP2Q5EKJDBCHGM6UNELFR7DES2U4L7Y/