That has always been the problem with competently executed DDoS attacks. You need a very large pipe as Step #1 which is simply not cost effective for most businesses. :/
That has always been the problem with competently executed DDoS attacks. You need a very large pipe as Step #1 which is simply not cost effective for most businesses. :/
It get even better if you're publishing through a mobile app - that one can simply switch from one host to another on the fly without customer even being aware of the problem beyond a slight delay in connection. The list of hosts of would need to be distributed out of band as a tiny payload, either through a high-cost high-bandwidth channel (but in a very low volume, obviously, just the name of the new host), or via DNS TEXT records so that they are hard to decipher reliably and require custom programming and raise the cost of the attack. There might even be hosts that will hold your alternate host list for free, such as the iTunes App Store (app description or even an in-app purchase "description" field).
Speaking of high-cost high-bandwidth providers, I think another option would be to host a CAPTCHa there, and those who solve it, or have cookies to prove that they did, or have logged in with a valid account, get redirected to one from the rotating lists of your normal hosts, with names and IP addresses changing every few minutes. An AJAXy application can then try different hosts in turn or in parallel before following a link.
Functioning healthy markets require regulation, protection of property rights, fair and impartial court system, enforcement, etc, etc.
In other words, just like there's no free lunch, there's no such thing as "free markets".
People sell DDoS mitigation but that isn't anything close to a business being able to mitigate things and caring about best practices.
Also, what are you talking about? Are you claiming that NTT nor TWTC can mitigate a DDoS attack? If so, you're massively wrong.
Both are in possession of large networks which allow them to mitigate DDoS attacks.
The small business with the 1gbps pipe isn't "mitigating" the attack. Their provider is mitigating the attack in return for payment.