Hacker News new | ask | show | jobs
by rdl 3832 days ago
We don't, generally. It would be challenging.

If it were a volumetric attack, you could walk back links to find the source. But for anything but a huge attack which lasted for weeks/months, that would be inefficient use of resources.

Paul Vixie is really at the forefront of pushing for providers to solve this problem. Until that happens (and they've tried for a decade), it will remain technically difficult/impossible, so you need to use other solutions to mitigate attacks.