@varbin @f4grx @nixCraft @torproject Well, you can dynamically block them based off packet rate & amount of requests and rate-limit them as well as limit them in terms of transfer rate.
- Also #DDoS-Protection is something any decent #datacenter & #hoster offers (don't use value-removing middlemen like #CloudFlare as they are a #RogueISP who ain't even goox at their job!)
Not to mention you rarely see DDoS attacks from residential IPs and ISPs are quick to disconnect offending hosts upon reporting them, so worst-case one blocks a /24 for 24 hours.
- This doesn't even account for the fact that #Skiddie-Tools like #LOIC are easily dstinguishable and filter for.
Again: if this is a real problem, any decent datacenter / hoster / upstream will gladly pick up the phone or reply to your support request via mail.
- After all, they too don't like it when someone hammers their infrastructure, so they have a vested interest in #Blackholing bad traffic at the #IX level.
#DECIX even officially recommends that as a means to handle large-scale DDoS attacks and keep everyone else online.
- To me a "#Layer7" solution like #Anubis comes way too late as it already incurs billable traffic at many hosters and datacenters and we don't want to cough up money because of someone else trying to #blackmail us (which is the #1 reason for DDoS'ers to do so!)…