How do we know it's a DDOS and not some sort of operational failure? Mods should change the title until it is confirmed.
> 20:51 PDT - We are investigating reports of connectivity issues to GitHub.com.
No mention of DoS or DDoS.
If you really want to protect your service (your own DNS or say SMTP, WebSockets, TCP), then you need to change the internet routing. This is done via BGP announcements of your IP subnets, such that you announce your inbound routes via the mitigation providers. The providers scrub the traffic and deliver clean traffic via a GRE tunnel to your routers. The outbound traffic is routed directly via your upstream providers.