The most common thing we've been seeing lately is gamers.   They are in
playing games online, and piss someone off, so they launch a DDOS towards
our customers IP to knock them out of the game.   They just don't realize
that it also fills up our pipes and does way more than knock a single
customer offline.

I've found that it's usually all UDP traffic, so I can filter for UDP and
usually get a pretty quick sense of what IP it's all destined for on our
network.   Just look for the single destination IP that has traffic coming
from hundreds and thousands of different source IP addresses.


On Mon, Jan 26, 2015 at 12:29 PM, David <[email protected]> wrote:

>  Its been a long time since I have seen one our network have an attack
> like that
>  but we try do all we can to prevent this by doing levels of route
> filtering and firewall filtering.
> It can easily happen with a router like a customers mikrotik with no rule
> to drop incoming dns request to the router.
>
>
> On 01/26/2015 01:02 PM, TJ Trout wrote:
>
> I usually use mikrotik torch to find the victim ip and have my upstream
> null it, what options are available for mitigation besides null routing at
> the upstream provider ?
> On Jan 26, 2015 10:50 AM, "timothy steele" <[email protected]>
> wrote:
>
>>  What filter do you guys use on wireshark to find a DDOS attack? It's
>> been about 7yrs sense I've done that so I'm a bit rusty..
>>
>>  Thanks,
>>
>> —
>> Sent from Mailbox <https://www.dropbox.com/mailbox>
>>
>
>

Reply via email to