Here's the partial-implementation of Countermeasure 2 in geth: https://github.com/ethereum/go-ethereum/pull/16069
Of note, this fix is still susceptible to attacks, though still an improvement:
> Since geth v1.8.0 still allows the attacker to freely craft node IDs that land in specific buckets, the partial implementation of Countermeasure 2 in geth v1.8.0 means that for a given victim’s table, there can be at most 10 attacker node IDs associated with each attacker IP address. While this improves on the situation prior to geth v1.8.0 (where we could eclipse our victim using just one or two IP addresses), it does not raise the bar for attackers quite as high as we had hoped.
Still making my way through the paper and the PR to identify other things fixed. Here's the entire 1.8 release: https://github.com/ethereum/go-ethereum/releases/tag/v1.8.0