Over a decade of DDOS--any progress yet?

Dobbins, Roland rdobbins at arbor.net
Wed Dec 8 10:53:34 CST 2010

On Dec 8, 2010, at 11:47 PM, Jay Coley wrote:

> This has been our recent experience as well. 

I see a link-filling attacks with some regularity; but again, what I'm saying is simply that they aren't as prevalent as they used to be, because the attackers don't *need* to fill links in order to achieve their goals, in many cases.

That being said, high-bandwidth DNS reflection/amplification attacks tip the scales, every time.

> Lastly there is usually always someone at the other end of these attacks watching what is working and what is not

This is a very important point - determined attackers will observe and react in order to try and defeat successful countermeasures, so the defenders must watch for shifting attack vectors.

