Overview
Syllabus
Lessons from Surviving a 300Gbps DDOS Attack
The Story 1. The nature of the attack 2. What we did to stop it 3. Practical steps to protect your own networks
March 18-21
What you don't need... 1. Botnets 2. A lot of people 3. Significant technical skill
Misconfigured DNS servers running without limits on what they respond to
Ingredients for the Spamhaus attack?
Attacker could do the math
Caused temporary regional disruptions
Worked with IXs and providers
"Next Hop Self" internal routing
Edge filtering of IPs/protocols with an understanding of our application
Four suggestions
Second, practice good protocol hygene...
Third, implement infrastructure ACLS...
Fourth, know your upstreams...
Taught by
Black Hat