This post originated from an RSS feed registered with Python Buzz
by Ng Pheng Siong.
Original Post: DDoS II
Feed Title: (render-blog Ng Pheng Siong)
Feed URL: http://sandbox.rulemaker.net/ngps/rdf10_xml
Feed Description: Just another this here thing blog.
I wrote this poorly: "In essence, when a DDoS attack is detected, routing
changes are made and propagated via BGP to redirect the attack traffic to a
blackhole node, away from the intended target." The effect of that
would be to DDoS the blackhole. Not so clever.
The correct description is that the blackhole drives the routing
change and causes routers at the edge of the network to drop the DDoS
traffic. Imagine the blackhole telling all those routers, "Send all traffic
of such and such characteristics to /dev/null." The blackhole is a controller, not a destination.