Re: [Hampshire] DDoS survival strategies

Top Page
Author: Damian L Brasher
Date:  
To: hampshire
Subject: Re: [Hampshire] DDoS survival strategies

Reply to this message
gpg: failed to create temporary file '/var/lib/lurker/.#lk0x5780a100.hantslug.org.uk.2490': Permission denied
gpg: keyblock resource '/var/lib/lurker/pubring.gpg': Permission denied
gpg: Signature made Mon Sep 5 18:32:45 2011 BST
gpg: using RSA key E5B6AC918A7E551C
gpg: Can't check signature: No public key
On Mon, 2011-09-05 at 15:40 +0000, Andy Smith wrote:
> Hello,
>
> On Mon, Sep 05, 2011 at 04:11:39PM +0100, Damian L Brasher wrote:
> > What general growing problems do systems engineers face in the future?
>
> I think that there are a lot more options for scaling these days,
> but the challenges are also different. As ever we must do more with
> less, which means actively working with other disciplines instead of
> treating it as an "us and them" situation. So that would be the
> "devops" movement - developers and operators need to understand each
> other and work together better if decent scaling is to be achieved, as it
> has to be done at both the application and system layer.


Yes, to adopt more collaborative way of working will help. Often in
organisations you get the impression that the expense of devops
'cross-pollination' is perceived to outweigh the benefits.

> "Cloud" is not something to be afraid of, but not something to be
> complacent about either. There is going to be a balance between
> owning your own hardware platform versus renting bits of someone
> else's platform as a service.


Trying to balance the complexity and cost of implementation with the
benefits of fast/easy end-user adoption and continued use. The margins
are hard to calculate.

> > Will IPv6reduce DDoS attack success or enhance the attacker's tool kits?
>
> There are a couple of new abuse angles with IPv6 but I expect that
> the old favourite of massive amounts of small UDP packets from a
> botnet will remain the big killer for many years to come, whether
> over IPv4 or v6.


Hmmm, I'll try to find a paper regarding this area for background study.
It's probably well documented somewhere.

> > What do you think? - is DDoS a global or local problem; or both?
>
> It is local to this Internet (I don't understand the question).


Well, indeed... the politics regarding geographical, attack source
reference, are probably beyond the scope of this discussion.

Best
Damian
--
Interlinux Engineering Foundation http://www.interlinux.org.uk

Central, non-trading, administration, governance and dissemination of
foundation intellectual property and know-how.

GPG 8A7E551C