
8/6/2012 · John Graham-Cumming
What this post added
This post analyzes attack statistics from July 2012, highlighting that a significant portion of attacks originate from 'Martian IP addresses' (invalid on the public internet, often due to spoofing or internal network usage). It details the mechanics of IP spoofing and explains how reflection attacks, particularly DNS amplification, are used to amplify attack bandwidth and obscure the true source. The post emphasizes that source IP addresses in Layer 3/4 attacks are often unreliable, contributing to Cloudflare's understanding of threat landscapes.