http://blog.cloudflare.com/technical-details-behind-a-400gbp...
"On Monday we mitigated a large DDoS that targeted one of our customers. The attack peaked just shy of 400Gbps."
And yes, it did affect other parts of their network, but they were able to successfully mitigate it.
"We saw attack traffic hitting every one of CloudFlare's data centers. While we were generally able to mitigate the attack, it was large enough that it caused network congestion in parts of Europe"
It's akin to setting up an IDS/IPS before you get pwnt through sloppy PHP/MySQL injections.
Where can I find more information about this? I've been thinking about exactly this issue with regards to running an MMO. Pretty much none of my functionality can be cached, so I don't think CloudFlare can help me. The best solution I've come up with is to run my MMO as a few servers on NFO, which hosts game servers and has a good reputation for "not just nullrouting you."
We have plenty of clients like that. They are using us for a variety of reasons, DDoS protection is one.
Curious: who is "we?"
If you're running game servers, your only good choice is to host with someone that has a really good onsite mitigation system. The offsite solutions add too much latency there.
Isn't that the whole point of using a preventative approach when it comes to your site's security? So you don't learn the hard way?
Of course knowing a lot of InfoSec guys, they can only tell them what they should have, it's up the owner's to make the call to get it in place. I don't know how many times one of them complained about doing a pen test on someone's site, making the recommendations and then one year later, they haven't fixed anything yet.
I'm not sure I'd classify being subject to DDOS as a security hole.
Cue George Santayana quote.