Cloudflare Reports Massive Slowdown in Network Level DDoS Attacks
blog.cloudflare.com
blog.cloudflare.com
It's almost like the entire Internet doesn't immediately handle every vulnerability as soon as it comes out...
Handling these attacks is difficult and a cdn is cheap.
L7 DoS requires more sophistication, because the attack code needs to stateful (iow. establish sessions) and craft requests that are better targeted. These in turn require either real effort or tools that reduce the effort.
All of this implies one thing: packet flood mitigation has finally become so ubiquitious that dumb flooding is no longer lucrative. So one could say that due to lack of low-hanging fruit the attackers are now moving up in the value chain.
So if you download the wrong app, your phone is now part of a botnet and that bandwidth you pay for is part of a DDOS attack. Scary.
But yeah, more developers should be aware of the possibility of this.
If you're a serious target these days, you basically need to have your services behind one of the big solutions. Rolling your own is far too expensive for any but the largest players. Cloudflare, GCE, and I'm sure many others offer ddos mitigation for grownups.