Hacker News new | ask | show | jobs
by hafabnew 4831 days ago
If this was part of a DNS Amplification DDoS, the source address is spoofed, and is in fact the target of the DDoS attack.
1 comments

Fair point, so to make this successful you would have to do UDP packet inspection on egress from your network to localize to the connection into your network where someone is spoofing source IPs. Clearly you can't do that on peering points (whose to say it is or isn't legit) but certainly from the ISP's connections into the Tier2 that could highlight bad ISPs and if those ISPs don't play ball you can cut them off from network access.