Website Security & Threat Management
No Scrubs: The Architecture That Made Unmetered Mitigation Possible

No Scrubs: The Architecture That Made Unmetered Mitigation Possible

9/25/2017 · John Graham-Cumming

What this post added

This post details Cloudflare's architectural approach to DDoS mitigation, highlighting the shift away from traditional 'scrubbing centers' towards an integrated, network-wide solution. It explains the challenges of bandwidth, cost, and knowledge associated with scrubbing centers and presents Cloudflare's 'unmetered mitigation' strategy. This involves leveraging every server in the network for mitigation, load balancing attacks across data centers and servers, and employing custom software (iptables, EFVI) for efficient packet processing. The post also emphasizes the benefits of this integrated approach, including cost-effectiveness, always-on protection, and continuous improvement of the entire software stack through real-world attack mitigation. It also touches upon Cloudflare's commitment to open-sourcing security tools.

Read the original post ↗