Digital Attack Map
digitalattackmap.com
digitalattackmap.com
> Does an attack's source country indicate the location of the attacker? (...) The source of an attack can (and often is) forged to appear as though it is initiated from a different location and, when accurate, usually represents the location of an infected computer being used in a botnet
I also find it weird to speak of attacks on/from countries, surely the targets are specific sites or services? Right now it looks like cyber warfare between countries.
DDoS often uses DNS Reflection to amplify the bandwidth of the attack. The source of the attack will be a) distributed b) not the actual attackers.
It's pretty but mostly meaningless.
This is true, but DNS reflection is dependent on aloof admins running open DNS resolvers. To say they're "not the actual attackers" when they're enabling the attack is not entirely accurate.
At the very least the target of the attacks, which is obviously not obscured, is meaningful information.
EDIT, disclosure: Arbor Networks (one of the partners here) is my employer. I am not a PR guy, my opinions are my own, yadda yadda etc.
And Arbor Net is one of the 'trusted' partners
On my server logs, I find a large part of such automated attack bots originating from Russia.