[dns-operations] Configurable TC=1?

Ralph Babel rbabel at babylon.pfm-mainz.de
Mon Dec 21 04:33:00 UTC 2015


Paul Vixie wrote:

> this won't help all victims of dns amplification
> attacks, since many of the congestion points are
> measured in PPS not BPS.

One response packet for one query packet doesn't
sound like much of a PPS amplification to me.

If PPS is a victim's bottleneck, then attackers might
just as well use their primary bandwidth without any
type of reflection (disregarding fragmentation, which
can already be taken care of by "max-udp-size" today).



More information about the dns-operations mailing list