> We've tested from the outside. In fact that was a real attack. Botnet
> consisted of ~10-12k bots each opening 1000 connections/second.

This kind of DDoS seems popular lately. Did it originate from a specific
AS, did you try to nullroute? I'm curious because mostly when I see
botnet attacks, they are not widely spread throughout the internet but
mostly come from <10 AS.

Nice to see that AWS performed here, thanks for sharing. :)

