Experiences with DDoS platforms...

So, it would appear to me that simply analyzing netflow data, etc.,
at the time of a (D)DoS attack, and then black-holing (by hand) the
offending source addresses may not be the most scalable and
efficient way of dealing/coping/mitigating/staying-on-the-air
during an attack.

Of course, depending where you are on the food chain, the resources
one is trying to protect, the volume of DDoS traffic, etc, plays into
the equation, etc.

I was looking to see what opinions folks on the list may have on
the DDoS "appliance" vendor products available -- I'm particularly
looking for a stand-alone (or in conjunction with a 'traffic analysis'
box) to off-load DoS "mitigation" -- real-world experiences welcome.

Please direct responses to me off-list, or not...

Thanks,

- ferg

Hey Ferg,

when you get some boxes to play with I'd be happy to help load them with a 10G DDoS; it would be phun...

I'd also be interested to work with researchers on instrumenting the attack. I think I know how to pitch one, just never had a willing catcher.

I'd especially enjoy it if you could publish your results of such research.

best,

-rick

Fergie wrote:

[...]

I was looking to see what opinions folks on the list may have on
the DDoS "appliance" vendor products available -- I'm particularly
looking for a stand-alone (or in conjunction with a 'traffic analysis'
box) to off-load DoS "mitigation" -- real-world experiences welcome.

Two jobs ago, I was at UKSolutions (aka UKS). One of UKS's products is the UKShells brand which is a script kiddie magnet and has a good number of IRC servers running on the accounts. IRC servers are a DDoS magnet as you probably know, so UKS got rather good at automating DDoS mitigation so nobody has to get out of bed to deal with it nor do any customers really notice.

The exact details of the system a bit of a mystery to me, but it was a multi-faceted approach that did a fair bit of analysis of the traffic and quite selective in its filtering, and was most definitely rather effective against DDoSes that should by rights have crippled the whole ISP, never mind the single box that was being targetted.

You'll be wanting to speak to Dan Lowe.