
3/27/2013 · Matthew Prince
What this post added
This post details Cloudflare's mitigation of the massive Spamhaus DDoS attack, which peaked at 120Gbps and threatened to disrupt internet infrastructure. It highlights Cloudflare's Anycast technology's ability to absorb such attacks and details how attackers shifted tactics to target Cloudflare's upstream peers and Internet Exchanges (IXs), including LINX, AMS-IX, and DE-CIX. The post emphasizes the scale of the attack, its impact on Tier 1 networks and IXs, and Cloudflare's role in developing best practices to secure IX infrastructure. It also reiterates the critical problem of open DNS recursors as an enabler of these large-scale attacks.