Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Creating own Game DDoS Protection Infrastructure

2»

Comments

  • @OpaqueRegistrant said:
    You can find server NICs up to 800Gbps if you spend some money (400Gbps Ethernet NIC for $2250, it's a lot but it's not a lot a lot). The problem is not the server's network card, it is how much internet you can actually get.

    To handle 1Tbps of DDOS traffic you first need to have 1Tbps of bandwidth. It doesn't matter how fast the server behind that pipe is, if the pipe itself is too small. Getting 1Tbps of bandwidth costs a lot but it has good economies of scale. That's why there are a few big DDOS protection providers instead of a lot of small ones.

    But obviously it's not completely impossible, since there are some providers. If you're willing to fail several times you could get your ASN and IP range and the fattest single pipe you can (or two pipes, to justify your ASN allocation), wait until you get DDOSed, then start the feedback loop: see what the attacker did, work out how to mitigate it, deploy the mitigations, repeat until it works well.

    DDOS mitigation is all about divide and conquer, by dropping the packets as close to the source as possible, when it's still many small floods instead of one big flood. You need to care about how the networks are interconnected and how much you can influence network routing. You can't just advertise your range over BGP and let the packets flow in, you need to know the story of where they're coming from and how they're getting to you, then you can start to manipulate that. The first thing you'd need is a dashboard showing you the source addresses that are sending you the most packets as well as the last-hop physical links that are delivering them to you. As programmers we often think IP addresses are just random numbers, but it is possible to look them up and see which network they come from, and BGP provides more information as well.

    The most basic mitigation is something called Remote-Triggered Black Hole or RTBH, which is a type of BGP announcement that tells your upstream network provider to drop packets based on a few limited criteria. Since your upstream drops them for you, you get to utilize their whole bandwidth. Say you have Hurricane Electric as an upstream, and they have a 10Tbps total capacity with Verizon, and Verizon is sending you 100Gbps of attack - if you use RTBH, HE will absorb all of that for you. Of course nobody on Verizon will be able to access your servers while the attack is happening, because HE's routers are pretty dumb and only know to drop all traffic that matches this route. But you can tell them it's only for Verizon, and then British Telecom customers will still be able to. But in reality you're probably getting DDOS packets from the whole world including BT, but you don't have to block the whole world, you can use RTBH on the biggest source networks until the rest of the attack small enough that you can manage it yourself.

    For more advanced mitigation, you can do something similar but instead of using RTBH, you actually have a server closer to the source network and you use BGP to get the traffic to go to that server. So in the same example, maybe you have a 100Gbps server at some IX that Verizon is connected to, and you can tell HE to block your route announcement to Verizon (this isn't the same as dropping packets), and then you announce the route at that IX instead (either to Verizon specifically, or to the whole IX). Then you get to filter that traffic yourself and send the legitimate traffic to your main location through a tunnel, instead of stupidly dropping it all, and Verizon customers will be able to access your server if the filter thinks they're legit, even at the same time as a DDOS is going on.

    Until you get to the size of Cloudflare (absolutely massive), you won't be able to keep 100% availability during a big DDOS - you'll only be able to reduce the damage compared to what your customer would have without your protection. There's no real cure for DDOS, you can just amputate a leg to save the rest of the body.

    My budget doesn't allow for all of that yet; right now, I'm looking for a low-cost solution. Regarding blackholing, though—are there any providers that offer GEO/ASN filtering?
    If so, I could block traffic from the US and EU, since my users are exclusively in the APAC region.
    Currently, most attacks are originating from Brazil, Mexico, Russia, Ukraine, Argentina, and India.

  • @Lostone said: Currently, most attacks are originating from Brazil, Mexico, Russia, Ukraine, Argentina, and India.

    are u okay with Germany in any case or sweden ?

  • luckypenguinluckypenguin Member
    edited September 20

    @Lostone said: Currently, most attacks are originating from Brazil, Mexico, Russia, Ukraine, Argentina, and India

    If your audience is mainly from APAC region, why not make a geoip based firewall rules?
    This is not a 100% solution but will save lots of wasted resources.

  • @luckypenguin said:

    @Lostone said: Currently, most attacks are originating from Brazil, Mexico, Russia, Ukraine, Argentina, and India

    If your audience is mainly from APAC region, why not make a geoip based firewall rules?
    This is not a 100% solution but will save lots of wasted resources.

    Because you still need enough bandwidth to receive all the packets so they can get to your firewall.

    @Lostone: have you asked your provider what they can do for traffic blocking?

  • @itzsenu said:

    @Lostone said: Currently, most attacks are originating from Brazil, Mexico, Russia, Ukraine, Argentina, and India.

    are u okay with Germany in any case or sweden ?

    Sometimes that, too.

  • @luckypenguin said:

    @Lostone said: Currently, most attacks are originating from Brazil, Mexico, Russia, Ukraine, Argentina, and India

    If your audience is mainly from APAC region, why not make a geoip based firewall rules?
    This is not a 100% solution but will save lots of wasted resources.

    Yes, that's my plan, but it would be better to use a Geo Filter on the upstream side, wouldn't it?

  • @OpaqueRegistrant said:

    @luckypenguin said:

    @Lostone said: Currently, most attacks are originating from Brazil, Mexico, Russia, Ukraine, Argentina, and India

    If your audience is mainly from APAC region, why not make a geoip based firewall rules?
    This is not a 100% solution but will save lots of wasted resources.

    Because you still need enough bandwidth to receive all the packets so they can get to your firewall.

    @Lostone: have you asked your provider what they can do for traffic blocking?

    Not yet; I'm currently looking.

Sign In or Register to comment.