#ddos

47 posts · Last used 3d

Back to Timeline
Drew 🇵🇭 @drewph@ieji.de · 4d ago

#Today #3Things

  1. I managed to isolate a residential proxy botnet that was hammering one of my client servers, and after adding some new htaccess rules, I've got CPU and RAM use down from 95% to about 25% and no more 503 errors. #Tech #WordPress #VPS #Hosting #DDoS

  2. Monitoring my posture more carefully while at my desk working (and playing). My #interoception is a bit unreliable like many #neurodivergent folk, but a mindful body scan approach may help, if I can stay aware of it. My trouble is that I get so absorbed in what I'm doing, nothing else exists.

  3. View from one of my study windows this morning. More controlled and supervised burning in the southmost hectare, in preparation for cultivation. #Farming #FarmLife

0
0
0
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Aug 06, 2026
Making Volumetric Attacks Useless The Active-Defense Playbook Proven Against Global Terabit-Scale Floods

Public Release · 2026-08-06

  1. The Problem Nobody Wins With Bandwidth

Volumetric attacks (DNS/CLDAP/NTP/SSDP amplification, botnet UDP floods, terabit-scale SYN storms) are the one attack class that has historically been mathematically unwinnable by defense. The economics are simple: An attacker rents a botnet or open amplifiers and produces terabits of traffic for pennies. A defender buys capacity and scrubbing to absorb it — at enormous cost, for as long as the attacker chooses to keep paying. The attacker always wins the bidding war, because producing one bit of attack traffic costs them a fraction of what absorbing it costs you.

Every solution built on absorption eventually loses. The answer is not to win the bandwidth war. The answer is to stop fighting it. The approach documented here — proven in production against sustained, escalating, terabit-class attacks — makes volumetric attacks structurally unprofitable and operationally useless.

The core principle: Never absorb. Reflect, reshape, redirect, and raise the attacker's cost per bit until their own volume is their own destruction.

  1. The Three-Layer Economic Flip

A volumetric attack is only unstoppable when the defender bears the cost. We flip all three cost surfaces:

  1. Turn their volume into their liability. Every byte they send is mirrored back at their own infrastructure with spoofed, untraceable identity — their amplifiers, their botnet C2, their own reflectors now have to eat the very flood they launched.

  2. Make their tooling lie to them. Inject benign, protocol-valid responses (successes, redirects, sinkholes) so the attacker's feedback loop reports failure or confusion instead of it working. An attacker who can't tell if the target is down keeps paying for an attack that stopped mattering.

  3. Make each of their packets cost more than ours. Deploy per-packet cost engineering so that processing their flood is expensive for them, not us. When their marginal cost per bit exceeds ours, the economics invert — and the attack dies on its own.

  4. Tiered Escalation That Never Blinks

Attacks are classified instantly by volume and answered with an escalating countermeasure wave — designed so terabyte-scale floods still resolve to the top tier with no ceiling:

T0: below attack threshold — normal traffic handling — no counter-fire T1: 1+ Gbps — core reflection + reshaping + cost-engineering wave T2: 100+ Gbps — adds connection warfare, tool corruption, legal injection, full-spectrum dampening T3: 1000+ Gbps, terabyte-safe — adds deception labyrinths, exfil traps, whole-fleet engagement, evidence & legal armada

Every tier runs in a detached, bounded scheduler — the event loop never blocks, so even a terabit-scale overlord response adds zero milliseconds of latency to normal defense. A flood cannot delay anything else.

  1. The Countermeasure Toolkit

Each technique is packet-level, rate-governed, and delivered from rotating/ghosted identities so the defender can never be identified by their own counter-fire.

4.1 Reverse Reflection — Their volume, their problem. For every packet received, craft a spoofed response that mirrors the attack back at the attacker's infrastructure. Scales linearly with their volume — terabit in means terabit reflected. The attacker's own pipe, amplifiers, and infrastructure become the target of their own flood. Combined with self-reflection, the attacker's own source identity fires at itself — they fight a war against themselves.

4.2 Traffic Reshaping — Make their tooling blind. Inject protocol-valid benign responses (HTTP 200/301/403, DNS NXDOMAIN, ICMP echoes) into the flood to dilute the attack signal and poison the attacker's feedback. Their tooling reports false status, false progress, and false success — so their automation keeps spending on an attack it cannot measure.

4.3 Protocol Redirection — Route them into the void. Inject forged ICMP redirects and protocol-level withdrawals that steer the attacker's traffic into distributed sinkholes and blackholes. Simulated upstream blackholing at the edge — no dependence on a provider scrubbing center.

4.4 Kinetic Dampening — Every packet now costs them. Per-packet cost scaling: high-volume attackers become progressively more expensive to their infrastructure, via source-quench and zero-window engineering that forces their side to buffer, retransmit, and consume resources.

4.5 Economic Exhaustion — Billing them for the attack. Inject CPU-costly TCP option and fragmentation engineering so that each attacker-side packet triggers disproportionate processing on their infrastructure. Their cost curve climbs while ours stays flat.

4.6 Absorber Grid — Sink the surplus. Dedicated sink grids and sink ports absorb and dissipate surplus flood energy that can't be reflected, so even the unavoidable residual is absorbed at minimal cost — on our terms, not the attacker's.

4.7 Kernel Enforcement — Cease fire at the wire. Automated null-routing and blacklisting at the network stack for confirmed offenders — traffic never reaches the application at all. Repeat offenders escalate to infrastructure-level isolation.

4.8 Full-Spectrum Dampening & Emergency Overlord — Everything, at once. For catastrophic floods, the Emergency Overlord deploys the entire countermeasure arsenal simultaneously: reflection, reshaping, cost-engineering, connection warfare, deception, legal notice injection, evidence capture, and whole-fleet engagement — a coordinated full-spectrum wave rather than isolated packets.

4.9 Fleet Engagement — Defeat the campaign, not the packet. Volumetric attacks come from botnet fleets and rotating sources. The response engages every known member of the attacking campaign simultaneously, so the fleet is defeated as a unit and cannot just rotate a new source IP.

  1. The Learning Loop — The System Gets Smarter Every Flood

Every engagement is scored and folded back into an adaptive rule engine. Attack volume is classified into bands, and a learned rule is minted for each trigger, tier, volume-band combination so repeat patterns are auto-hardened before they peak. Volume bands start at baseline and escalate through major, severe, and catastrophic thresholds — the system's response to each band is continuously refined by real engagement outcomes. Countermeasure effectiveness per attack type is tracked and the statistically best response is auto-deployed. A flood that worked once is pre-countered the next time it tries.

  1. Why This Can't Self-Destruct — Resource Governance

The reason most fight back schemes fail is they become the victim of their own counter-fire. This design hard-codes self-preservation:

  • Hard global output ceiling — total countermeasure throughput is rate-capped regardless of how many attackers, so the defender can never saturate their own link.
  • Per-target caps — no single adversary can consume the whole budget.
  • Load-aware circuit breaker — when system CPU/memory pressure crosses critical, counter-fire halts entirely and passive defense continues. Under heavy load the budget is automatically throttled.
  • Micro-pacing under pressure — packet emission is spread out under load instead of bursting.

The platform has pushed 336+ million countermeasure packets through this governor with a 99.97% budgeted-throughput pass rate — maximum fire, zero self-inflicted damage.

  1. No Blowback — The Ghost Layer

Reflecting and disrupting requires the counter-fire to look like the attack. The Ghost Layer makes that safe:

  • Rotating, spoofed source identities — no two transmissions use the same identity.
  • Handle-only records — the platform can prove an engagement occurred while storing only hashed identities, never anything traceable back to the defender.
  • Self-reflection uses the attacker's own identity as the source, so the attacker's logs point at themselves.

The attacker cannot learn who defended against them — which means there is no retaliation vector.

  1. Evidence & Legal Armada

Every volumetric engagement captures a permanent, jurisdictionally-framed evidence dossier: attack type, volume, tier, timeline, and countermeasure response. Confirmed offenders receive formal ISP/abuse/LEO reports with calibrated confidence. Attackers who wage floods on this system accumulate legal exposure with every terabit.

  1. Proven Operational Results

Real telemetry from the live platform:

  • 336+ million countermeasure packets delivered under governor control — 99.97% budgeted pass rate
  • 1,785 tiered flood engagements escalated through the tier system
  • 1,544 state-exhaustion operations · 323 null-routes · 521 oblivion-level isolations
  • 12.9 million phase-2 connection-warfare packets
  • Hundreds of learned volume-band rules minted from live flood engagements
  • Attacker fleets tracked, isolated, and driven off across every volume tier up to terabyte scale

Volumetric attacks against this system are not merely mitigated — they are made useless. The attacker pays the full cost of launching; the defender pays nothing to absorb; and every attempt teaches the system how to make the next one cheaper and more one-sided.

  1. Adopting This Approach — A Defender's Checklist

  2. Stop designing to absorb. Budget a fraction of what you'd spend on scrubbing capacity for counter-fire instead.

  3. Classify by volume tier and pre-define an escalating response wave for each tier, including a terabyte-safe top tier.

  4. Never block your own event loop. Run the heavy response in detached, bounded workers.

  5. Always govern your own fire. Hard global cap + per-target cap + load-based circuit breaker, or you'll lose to yourself.

  6. Never counter-fire from a real identity. Rotating/ghosted sources or don't counter-fire at all.

  7. Refuse spoofed targets. Only engage sources that are real enough to be held responsible — never burn counter-fire on spoofed decoys.

  8. Learn every engagement. Score outcomes and mint auto-escalating rules per volume band so repeat attacks are pre-defeated.

  9. Engage fleets, not packets. Isolate the whole campaign so rotation doesn't win.

  10. Capture evidence continuously. A legal trail makes the economics of attacking worse.

  11. Sweep your own telemetry. Measure cost-per-attacker-bit vs cost-per-defender-bit and keep it inverted — that is the only metric that matters.

WinterGateIC — Autonomous Defensive & Counter-Offensive Platform. This playbook is derived from a production system that has faced and neutralized sustained, escalating volumetric attacks. Figures above are real live telemetry. No infrastructure details, identities, or technical secrets are disclosed.

#VolumetricNeutralization #DDOS #ActiveDefense #EconomicWarfare #NetworkSecurity

0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 03, 2026
Nozomi details the Tengu botnet, a modernized Mirai variant. This IoT malware adds encrypted C2, proxy, anti-analysis, and self-defense to resist removal. #Tengu #Mirai #IoTBotnet #DDoS #Malware #CyberSecurity https://securityonline.info/tengu-modernized-mirai-botnet/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
ddactic @ddactic@infosec.exchange · Jul 31, 2026
Web API endpoints are the part of the attack surface that gets the least testing. Login forms get tested. APIs get a "passes the smoke test" check and ship. #cybersecurity #ddos #infosec ddactic.net?ref=mastodon
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 30, 2026
Discover how the new Dysphoria botnet infected 200,000 IoT devices, utilizing blockchain domains and proxy nodes to obfuscate its C2 infrastructure. #DysphoriaBotnet #Cybersecurity #Blockchain #IoT #DDoS https://meterpreter.org/dysphoria-botnet-blockchain-c2/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
ddactic @ddactic@infosec.exchange · Jul 26, 2026
A scrubbing center is not a guarantee. It's a routing decision, and most CISOs blur three different things into one. #cybersecurity #ddos #infosec ddactic.net?ref=mastodon
0
1
0
Stefan Gast @notbobbytables@infosec.exchange · Jul 25, 2026
RE: https://fosstodon.org/@sourceware/116982983262820236 AI scraperbots are effectively DDoS'ing sourceware, known for hosting essential software development projects like glibc, gdb, gcc and binutils. Just given how widely used some of the projects are, I am assuming that also some scraperbot authors use them. By overwhelming the servers hosting projects they rely on, too, they are cutting the branch they are also sitting on. What a time to be alive! 😩 #scraperbots #LLMs #AI #ddos
0
1
1
Nokia Deepfield @deepfield@infosec.exchange · Jul 21, 2026
New ERT report: #IranBot is a botnet built to be thrown away. Three builds in six weeks, no infrastructure reused, each one cruder and each one reaching further. The build stripped of encryption is the one worming today, and its C2 outlives none of the others by much. https://github.com/deepfield/public-research/blob/main/iranbot/report.md #threatintel #DDoS
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 21, 2026
Unit 42 exposed TuxBot v3 Evolution, an IoT botnet built with LLM help. AI-written bugs left the malware only 70% functional. See the full analysis. #TuxBot #IoTBotnet #Akiru #DDoS #Malware #Unit42 https://securityonline.info/tuxbot-v3-evolution-iot-botnet/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Adhidarma Hadiwinoto :verifyc: @adhisimon@mastodon.kodesumber.com · Jul 14, 2026
Suwek, lagi enak-enak rebahan nonton film tiba-tiba kustomer colo bawel network intermittent. Suweknya ternyata ada DDOS di sisi upstream kami. Suweknya lagi mimin mereka molor kagak bangun. What a tripple kill combo. #networkoutage #ddos
0
0
0