althost wrote:
Regarding the bigger picture, it's alarming that there aren't better auto-detection and auto-throttling of such volumetric attacks. We're all headed for major problems if that can't be accomplished.
Inter-datacenter connections depend on your upstream providers. From my 9 month long attack, I switched datacenters 3 times before I was on a datacenter capable of properly routing through attacks and filtering upstream. Even then, the volumetric attacks were so varied that I had to implement other measures to drop the remaining 5% of destructive traffic that crept in. And that wasn't without it's collateral damage (including other customers in that datacenter who specializes in DDoS mitigation).
Most higher tier bandwidth providers have auto-detection/auto-throttling/auto-scrubbing in place (assuming it's paid for) - however, attacks of this size and nature need manual intervention and attention to handle. The moment you think you have the problem taken care of, the attackers change their attack a bit.
It's a total pain in the ass to handle, and during the time I was hardest hit - I would be lucky to get 2 hours sleep a night.
(My attackers did post their extortion demands on my social media accounts, which actually garnered a lot of support for me to not to give in to their demands - not that they were asking for much. This is how extortion in the digital age works - ask for a small amount, see if you cave in, then continue the attacks and extort larger amounts.)