Skip to content

ExaDDOS : rationale

Thomas Mangin edited this page Feb 12, 2014 · 2 revisions

We wrote ExaBGP to complement our NFSEN installation. You can only search flows in NFSEN once the data has been fully analysed. For us, it meant that most of the time we had to wait 5 minutes before being able to find out the destination IP of the attack.

As we were seeing 15 mns DDOS, at least twice a day, by the time we had identified the DDOS, it was off. This is what prompted the creation of ExaDDOS, a tool which did not care about the collection of the data but which would just give us visibility in what is happening now.

Clone this wiki locally