Drdos Attack - How Do You Determine The Real Source Ip?


Here's a question for you guys...

If a person's DNS server is being used as part of a Distributed Reflected Denial of Service attack (DRDOS), is there any way to determine the real IP address where the DNS requests are coming from?

Technically yes but actually no.

You would have to monitor every router on the internet and determine which router got the spoofed packet first assuming that the first router it came from is not the same router that the legitimate source is on.

However, this is not possible because it is impossible to monitor at that level of detail within a single ISP let alone the whole internet.

@Kapeea, I would recommend you reading this article.


