[dns-operations] Configurable TC=1?
rbabel at babylon.pfm-mainz.de
Mon Dec 21 04:33:00 UTC 2015
Paul Vixie wrote:
> this won't help all victims of dns amplification
> attacks, since many of the congestion points are
> measured in PPS not BPS.
One response packet for one query packet doesn't
sound like much of a PPS amplification to me.
If PPS is a victim's bottleneck, then attackers might
just as well use their primary bandwidth without any
type of reflection (disregarding fragmentation, which
can already be taken care of by "max-udp-size" today).
More information about the dns-operations