[dns-operations] DDOS/Collateral Damage BCPs
regnauld at nsrc.org
Thu Apr 15 19:28:50 UTC 2010
Barry Raveendran Greene (bgreene) writes:
> Q. Has anyone done any recent work on "architecture" guides for SP's DNS?
> This crew is using bind, they are cluefull enough to break apart their
> customer resolvers and the slaves, and are willing to make changes.
Anycasting an Unbound setup works well -- just held a workshop
on this for MENOG in Riyadh.
What's the profile of the DDoS ? Any identifiable denominator in the
queries that would make it easier to filter on the upstreams ?
More info appreciated, eventually off-list.
More information about the dns-operations