Are there some good open source scrubbing center projects you might be able to recommend?
Also might you have any resources or links to how these scrubbing services are implemented, what heuristics they use etc?
I understand the front end of DDOS mitigation i.e netflows, BGP communities and RTBH, and GRE tunnels to the scrubbing centers. However the details of how the scrubbing centers works is something of a mystery to me.
When looking at any of the big DDOS provider's literature, the scrubbing centers are mostly just opaque boxes with little documentation on how they actually work.
Also might you have any resources or links to how these scrubbing services are implemented, what heuristics they use etc?
I understand the front end of DDOS mitigation i.e netflows, BGP communities and RTBH, and GRE tunnels to the scrubbing centers. However the details of how the scrubbing centers works is something of a mystery to me.
When looking at any of the big DDOS provider's literature, the scrubbing centers are mostly just opaque boxes with little documentation on how they actually work.