A DDoS with almost 100 Mbit/s of incoming traffic
Summary
During a DDoS attack, live monitoring of eth0 showed 93.72 Mbit/s of incoming traffic at 21,246 packets per second, while almost nothing went out. vnStat was watching the network interface in live mode. Outgoing traffic was only 44 kbit/s at 19 packets per second.
Ideas
- Highly asymmetric traffic can make an ongoing flooding attack visible.
- Packets per second add the load on the network stack to the raw bandwidth.
- A live view gives a quick overview but does not replace a permanent record.
- Data from the provider helps to judge the attack type and bottlenecks outside the server.
Insights
- An attack can exhaust resources before the nominal line bandwidth is fully used.
- Bandwidth and packet rate describe different costs of a DDoS attack.
- Without historical baselines, the scale of unusual traffic is hard to judge.
Facts
- The measurement was taken on 13 September 2016.
Recommendations
- During an attack, record bandwidth, packet rate, protocols and destination ports.
- Keep measurements for later analysis and for talking to your provider.
- Plan filtering and DDoS protection in front of the bottleneck of your own uplink.
References
Links to the original source and the Web Archive open in a new tab.