[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: How is this attack causing 900 Mbps download and 100 Mbps upload?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Does anyone have any advice? This attack seems to be getting worse.

If any developers would benefit from it, I can provide Tor Metrics with
a sampling interval of 15 seconds along with Tor debug logs during the
attack, along with the hour preceding it and the hour following it. If
so, please message me privately and I will send it PGP-encrypted.

In the meantime, the attacks have caused so many problems with my hosts
that I ended up needing to write a script that monitors bandwidth use
over the control socket. If the bandwidth asymmetry ratio exceeds 1:2
over a 2 minute sliding window and bandwidth rate exceeds 50 Mbps, it
stops the Tor process for 15 minutes before restarting it.

It seems to reduce the impact of the attack on my monthly bandwidth
quotas and prevents my providers from complaining to me about sustained
100% CPU use, but I fear it's effectively only making the DDoS more
powerful as it both reduces the attacker's own bandwidth costs and
guarantees my relays will be completely down whenever they attack (as
opposed to struggling but remaining barely up).

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCaqn5YAAKCRAw+TRLM+X4
xrffAP9B4L7sQNHi7WbNAWz+XXnbPOuFfpQ0k8CZWNYaqJIOPQEAvv6pLqXpXGes
sp+DxFlyHb2CNN8Lo1ips8Z+ONGmHQo=
=B7sJ
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx