This rules out small clouds for us.
So, we use GCP Azure AWS exclusively because of their ability to defy network level ddos.
This rules out small clouds for us.
So, we use GCP Azure AWS exclusively because of their ability to defy network level ddos.
Why? Mostly because of cost and it seemed simple than building out stuff on cloud services.
Every Friday night, our services got ddosed by our competitors.
Provider would nullroute our IPs and our service goes down
We struggled with it a lot since we were not big enough to afford a premium ddos solution.
Once we realized that big cloud like aws, gcp do not suffer from this, we had to make a switch.
When you say GCP, Azure and AWS have the capacity to defy the ddos, what capacity are you reffering to?
Are you talking about actually scaling and serving the bogus requests? Or capacity to have enoough bandwith and firewall power to fend it off?
You probably would have been better off using a cloud mitigator from the start. Their pricing is competitive when you factor in all of the costs.
They've very effective network level ddos detector/filtering
Shield (https://aws.amazon.com/shield/) is AWS's DDOS protection service. It's free and is basic protection against L3/4 attacks.
Shield Advanced (same URL as above) is a big step up in price, but gives you access to 'improved protection' and a global response team.
Cloudfront (https://aws.amazon.com/cloudfront) is a CDN with global edge locations.
WAF (https://aws.amazon.com/waf) is AWS's web application firewall service. It's less about DDOS and more about specific application attacks, but is part of the whole solution.
For more detail, you can have a look at AWS's DDOS whitepaper: https://d0.awsstatic.com/whitepapers/Security/DDoS_White_Pap...
So you're saved then.
I wonder how much DDoS it takes before a cloud provider starts dropping a customer’s packets now. Do they even bother anymore?