bk99.de entertain the web since 1997

A DDoS with almost 100 Mbit/s of incoming traffic

Summary

During a DDoS attack, live monitoring of eth0 showed 93.72 Mbit/s of incoming traffic at 21,246 packets per second, while almost nothing went out. vnStat was watching the network interface in live mode. Outgoing traffic was only 44 kbit/s at 19 packets per second.

Ideas

  • Highly asymmetric traffic can make an ongoing flooding attack visible.
  • Packets per second add the load on the network stack to the raw bandwidth.
  • A live view gives a quick overview but does not replace a permanent record.
  • Data from the provider helps to judge the attack type and bottlenecks outside the server.

Insights

  • An attack can exhaust resources before the nominal line bandwidth is fully used.
  • Bandwidth and packet rate describe different costs of a DDoS attack.
  • Without historical baselines, the scale of unusual traffic is hard to judge.

Facts

  • The measurement was taken on 13 September 2016.

Recommendations

  • During an attack, record bandwidth, packet rate, protocols and destination ports.
  • Keep measurements for later analysis and for talking to your provider.
  • Plan filtering and DDoS protection in front of the bottleneck of your own uplink.

References

View the original post