DDoS zombies generally send packets with forged return addresses [snip]
Not so. Maybe 20% of DDoS packets have forged source addresses. When you've got a network of 12,000 Slapper infected bots, you don't need to worry about obscuring the traffic's origins.
Blocking packets w/ spoofed source, or source address validation, is at best a small part of the solution.
Not so. Maybe 20% of DDoS packets have forged source addresses. When you've got a network of 12,000 Slapper infected bots, you don't need to worry about obscuring the traffic's origins.
Blocking packets w/ spoofed source, or source address validation, is at best a small part of the solution.
http://images.e-gerbil.net/ghetto
http://images.e-gerbil.net/ghetto Most of these have not been referenced by any links posted thus far.