
11/13/2021 · Omer Yoachimik
What this post added
This post details the mitigation of a nearly 2 Tbps multi-vector DDoS attack combining DNS amplification and UDP floods. It explains Cloudflare's out-of-path traffic analysis for sub-second detection, real-time signature generation, and ephemeral rule propagation to the edge. Specifically, it highlights the use of eBPF/XDP in the Linux kernel for wirespeed packet dropping of attack traffic.