logoalt Hacker News

literalAardvark • today at 9:14 AM • 0 replies • view on HN

The only way to deal with those is to blackhole the traffic at BGP level.

The fancy alternative is to anycast that network and do distributed filtering so that the flood is manageable.

The first can be done by your ISP but it does lead to the temporary loss of traffic via that IP.

The second one is what DDoS mitigation services do and AWS has a basic one built in ( AWS Shield ) and several additional services you can get.