logoalt Hacker News

BLKNSLVR • today at 2:23 PM • 1 reply • view on HN

Naive question: services that can be used for amplification attacks, are they constantly getting patched to prevent the latest iteration of attack type?

In other words, if there are a bunch of services prone to amplification attacks, can traffic from these services be upstream-blackholed for the duration of the attack?

If it's not traffic coming directly from an IoT botnet, which is probably where the source of the spoofed traffic that initiates the amplification, then isn't there likely a smaller, more manageable number of services responsible for the attack traffic?

Or are we talking services that form the substrate of the internet that have inherently exploitable protocols that it would take a large herd of organized cats in order to update in a way that doesn't break the internet, and will still take ~10 years?

I still think in IPv4, so this may be a stupid question, but it's it known how many unique IP addresses were attempting to connect in the space of that time, and then it's there logging to identify those with unusually large amounts of individual traffic?


Replies

nine_ch • today at 2:58 PM

[flagged]