By Sean Reifschneider Date 2013-01-11 12:28 Tags dns, linux, sean reifschneider, technical
We've recently been the reflection point in a DNS-based reflection+amplification attack. We implemented some rate limiting to prevent it, and as part of my research on this topic I found this discussion to be fascinating. In particular, the trade-offs between request rate limiting and response rate limiting... It's about half way down in this dns-operations thread on "DNS ANY from Amazon".
comments powered by Disqus