Hacker News new | ask | show | jobs
by t0mas88 1677 days ago
Some have, but it's usually signature based. If a customer has an infection with a known worm (all I've seen were windows based) it's matched by some signature and the connection is isolated. From then on all web traffic is redirected to the ISPs service portal helping the customer install an antivirus solution.

Never seen it applied to DDoS kind of things.