Re: DDOS solution recommendation

2015-01-10 Thread Paul S.
While it indeed is true that attacks up to 600 gbit/s (If OVH and CloudFlare's data is to be believed) have been known to happen in the wild, it's very unlikely that you need to mitigate anything close. The average attack is usually around the 10g mark (That too barely) -- so even solutions

Re: DDOS solution recommendation

2015-01-10 Thread Paul S.
Very true. Last year's Atrato outages in NY come to mind on this one. On 1/11/2015 午後 01:51, Roland Dobbins wrote: On Jan 11, 2015, at 11:37 AM, Paul S. cont...@winterei.se wrote: Obviously, concerns are different if you're an enterprise that's a DDoS magnet -- but for general service

Re: DDOS solution recommendation

2015-01-10 Thread Ammar Zuberi
I'd beg to differ on this one. The average attacks we're seeing are double that, around the 30-40g mark. Since NTP and SSDP amplification began, we've been seeing all kinds of large attacks. Obviously, these can easily be blocked upstream to your network. Hibernia Networks blocks them for us.

Re: DDOS solution recommendation

2015-01-10 Thread Paul S.
Seeing a lot of SSDP too, but attacks on scales that large have been rare (at least for us). Have however seen a few 40+ ones, yeah. I suppose it all comes down to how much you actually /need/ to stand up against. For enterprises that can't afford to go down, yeah... :( On 1/11/2015 午後

Re: DDOS solution recommendation

2015-01-10 Thread Roland Dobbins
On Jan 11, 2015, at 11:37 AM, Paul S. cont...@winterei.se wrote: Obviously, concerns are different if you're an enterprise that's a DDoS magnet -- but for general service providers selling 'protected services,' food for thought. Actually, bystander traffic is all-too-often affected by

Re: DDOS solution recommendation

2015-01-10 Thread Sathya Varadharajan
This gives some comparison of cloud based Ddos mitigation providers. https://www.ombud.com/product/compare/prolexic-ddos-protection On Jan 10, 2015 10:50 PM, Damian Menscher dam...@google.com wrote: On Thu, Jan 8, 2015 at 9:01 AM, Manuel Marín m...@transtelco.net wrote: I was wondering what

Re: DDOS solution recommendation

2015-01-10 Thread Charles N Wyble
Also how are folks testing ddos protection? What lab gear,tools,methods are you using to determine effectiveness of the mitigation. On January 8, 2015 11:01:47 AM CST, Manuel Marín m...@transtelco.net wrote: Nanog group I was wondering what are are using for DDOS protection in your networks.

Re: DDOS solution recommendation

2015-01-10 Thread Ammar Zuberi
You'd notice that most people don't really know how big the attack that they're sending is. I've done a lot of research into how these attacks actually work and most of them are done by kids who don't really know what they're doing. To them an attack is something that will take their target