Properly ignoring invalid requests can be a challenge, the process of doing so will depend on the type of attack being used. SYN floods can difficult since the src IP is most likely invalid. The attacks we've seen with DNS and NTP amplification are difficult as the attack isn't trying to get your servers to respond, they are just flooding your incoming pipe with data. If they are trying to abuse some page within your application you can more easily mitigate it as you'll know the source IP of the request so it can be blacklisted.
EDIT: a few more details:
SYN flood: http://en.wikipedia.org/wiki/SYN_flood
DNS Amplification: http://blog.cloudflare.com/deep-inside-a-dns-amplification-d...
As for mitigation, while we hear about Cloudflare a lot, AT&T and other large providers can provide DDOS protection for leased lines[0]. Basically what happens, before the data gets to your leased lines, traffic headed to you will go through AT&T's DDOS detection/prevention systems that attempts to filter bad traffic. This type of service would apply more to companies like Linode or possibly the datacenter that they are housed in.
[0] http://www.business.att.com/enterprise/Service/network-secur...
It appears Basecamp only has a /23, so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP. It's still possible to block, but not quite as easy as setting up Cloudflare.
Why would it be easier for the attacker to find their direct servers if they only have a /23 - doesn't Cloudflare obscure the identity/location/IP of the server on the other side?
Can the upstream to the actual server restrict traffic to known Cloudflare blocks?
The ISPs will help during a DDOS but response times are slow and we haven't tried getting them to put this type of block in place yet.
Relevant links: https://support.cloudflare.com/hc/en-us/articles/200172676-C... https://support.cloudflare.com/hc/en-us/articles/200170216-H... https://support.cloudflare.com/hc/en-us/articles/200170196-I...
I'll leave it to others to answer this (for this situation) but keep in mind also that adding cloudflare also adds an additional layer that can fail for different reasons.
That tradeoff may well be worth it for certain high visibility web properties but maybe not if you are a low value target.
There are pros and cons to any decision you make that depend on specific circumstances.
That's obviously very much dependent on the kind of attack and whether CloudFlare has more network capacity than Basecamp (which I would imagine is highly likely).
Because of the unique design of our network, I'm unaware of any other service that has as much capacity that can be utilized in aggregate to mitigate large-scale attacks.
Matthew Prince Co-founder & CEO, CloudFlare