DDoS scrubbing

Organizations have only two options for handling DDoS attacks: black-holing or scrubbing. As we have already discussed, black-holing does not scale well and could shut down the designated target to protect everyone else. The other solution is scrubbing, which uses separate DDoS cleaning engines. The tricky part is the BGP announcement, which diverts all network layer packets from the targeted IP address to your mitigation provider's scrubbing servers. The malicious packets are filtered out and clean traffic or non-DDoS is forwarded to actual services.

Cloud service providers, or internet service providers, often provision these scrubbers to a local data center. Industry has seen that DDoS attacks have scaled to > 1 Tbps traffic ...

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.