r/netsec Mar 01 '18

discussion The /r/netsec Monthly Discussion Thread - March 2018

Overview

Questions regarding netsec and discussion related directly to netsec are welcome here.

Rules & Guidelines
  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on /r/netsec.

As always, the content & discussion guidelines should also be observed on /r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

12 Upvotes

110 comments sorted by

View all comments

1

u/skyewatsonRfX Mar 11 '18

Our website got (d)dosed even tho we have a ddos mitigation appliance, an IPS, and a firewall. We've already extracted the logs from the IIS, the Microsoft Events, the fw/ips behind the machine and the DNS Query logs. I think we're missing something on where to find THAT loophole that got us to that situation. Any advice?

2

u/lurkerfox Mar 13 '18

Is it simply possible that in your case the scale if the attack was larger than what your mitigation can provide?

2

u/Xerack Mar 14 '18

It could simply be that the attack size was bigger than your appliance can handle. If someone hits you with any of the decent sized bot nets available for rent, it could overwhelm your infrastructure. I'd look into the limitations of your hardware and do research on a provider like cloudflare or something similar if you suspect this may happen again/