Absorbing floods.
WHAT THEY ARE
Attempts to overwhelm a service or its connection with traffic.
WHY THEY WORK
A connection has finite capacity, and filling it denies service regardless of the server.
WHAT THAT MEANS
You cannot defend against volume exceeding your connection, on your own equipment.
WHERE MITIGATION MUST HAPPEN
Upstream, at a network with capacity to absorb it.
WHAT PROVIDERS OFFER
Detection and filtering at their edge Diversion through scrubbing infrastructure Anycast capacity spread across locations
WHAT REFLECTION AND AMPLIFICATION ARE
Sending small forged requests to services that reply with much larger responses, directed at a victim.
WHAT SERVICES ARE COMMONLY ABUSED
Open resolvers, time services, and other datagram-based protocols.
WHAT TO DO AS AN OPERATOR
Ensure you are not a source: no open resolvers, rate limiting, and filtering of forged source addresses.
WHAT APPLICATION-LAYER ATTACKS TARGET
Expensive operations, repeated, at modest volume.
WHAT DEFENDS AGAINST THOSE
Rate limiting, caching, and efficient application design.
WHAT TO ESTABLISH BEFORE YOU NEED IT
What your provider covers, and how quickly it engages.