【正文】
? 錘子 – 釘子? ? layer3 layer4 layer7 抗攻擊手段 ? 參考 Google的內(nèi)部標(biāo)準(zhǔn) value – packets/second – bits/second – queries/second – IPs 抗攻擊手段 ? ACL –在接入層面的 3,4層快速過濾功 能 – iACL 抗攻擊手段 ? BGP(routing protocol) is your friend ? BGP to the rack (facebook) – BGP blackhole –( SRC based DST based) – – Diagram from 抗攻擊手段 ? BGP(routing protocol) is your friend ? CT Dst rtbh ? CT has loose urpf enabled, so it can do Src rtbh 抗攻擊手段 ? Flowspec – ACL on steroid – Layer4 info – Use bgp control plane to distribute ACL ? Benefits are huge ? Use BGP to distribute flow specification filters and dynamically take action(drop, sampling, redirect) on routers. Supported by Juniper and Alcatel ? Fast :ACL propgate via bgp advertisement ? We can block traffic by src|dst ip, src|dst port, packet size, protocol, tcp flags, icmp 他 type|code... and any of the bination – Amazon, cloudflare, goo