nanog mailing list archives

Re: Carpet bombing, what's it look like now


From: Saku Ytti via NANOG <nanog () lists nanog org>
Date: Sat, 1 Aug 2026 09:17:36 +0300

On Fri, 31 Jul 2026 at 21:51, Mike Hammett via NANOG
<nanog () lists nanog org> wrote:

vendor report. Does destination prefix plus protocol and port still get
you something tight enough to act on, and if so, how many rules do you
end up carrying mid-attack? Somewhat related, does packet length
matching actually work on your hardware? I've been reminded lately that
documented and functional aren't always the same thing.

Packet size matching in my experience tends to work on most gear,
particularly on gear you'd use on edge.
More so, flexible packet matching is increasingly available that
allows highly specific pattern matching,
if any is available.

What are you feeding detection with, and does it keep up? sFlow, IPFIX,

IPFIX. But sampling rate is making things tricky, as very short term
attacks are a thing.

Once you've got a signature, what do you actually do with it? Drop
outright, rate limit, or hand it to a scrubber? I'd expect that to

Customers who pay for scrubbers get scrubbers. If there is a specific
target, blackholes or ACL. If wide carpet,
QoS downgrade, no explicit rate-limit, transport the attack if we have
excess capacity to do so.

What's everyone doing for v6? Flowspec support looks thin enough there
that a carpet bomb against v6 space puts you back to blackholing hosts
one at a time.

Same as v4.

-- 
  ++ytti
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/2YP2Q5EKJDBCHGM6UNELFR7DES2U4L7Y/


Current thread: