Reply to post: Re: "One area might get hit badly, but not everywhere"

Experts to Congress: You must act on IoT security. Congress: Encourage industry to develop best practices, you say?

Anonymous Coward
Anonymous Coward

Re: "One area might get hit badly, but not everywhere"

A DDoS attack is designed to hit a single endpoint (or a few ones), but which is an important one. It's not something the spreads around. One way to minimize the effects of a DDoS is exactly a redundant infrastructure where even if some nodes are flooded others will keep on working - but that's not always feasible, moreover some redundant architectures are also designed for load balancing, therefore a number of user can still be affected until they are redirected other nodes (but the DDoS attack too may be redirected).

Internet routing tables can be modified (without severing cables...), and sometimes it happened for strange reasons (IIRC there were routes announced which made traffic going through Pakistan and China....), but it could also worsen the situation, when a surge of traffic is routed through a single link.

IMHO thinking to stop DDoS attacks only at the backbone tier is very difficult, and the spreading of unsafe IoT devices will make also less relevant - the possible sources will be many. many more scattered around many, many connections.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon