Three Days in August: What a DDoS Attack Exposed in Our Network
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Three Days in August: What a DDoS Attack Exposed in Our Network
Unofficial Hacker News client; not affiliated with Y Combinator.
nine_ch · · focus · HN ↗
The write-up is mostly about what we got wrong: our automated detection only covered our own prefixes, not customer prefixes we announce on their behalf. Blackholing at the IXs we connect to only took effect via route servers, not on direct peerings. And we had no way to withhold a prefix from one specific upstream, so we had to build that while under full load. On top of that, our own website runs on the same shared platform as customer apps, so when it was targeted, unrelated applications were affected too.
What eventually ended it was moving exposed applications behind a CDN with DDoS protection. The full timeline is in the PDF postmortem linked from the post. Happy to answer questions.