Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For many many years we ran our own DNS servers using PowerDNS with MySQL backends. That's all fine and well and it's a very powerful architecture and relatively reliable and strong to even high amounts of traffic... that was until we started regularly seeing 10Gbps+ DDoS attacks, so we put a DDoS protection service in front of the sites, but there wasn't really anything at the time capable of protecting the DNS servers as well.

So a few months go by, everything has been fine and then another DDoS hits. Looking through the web-servers, not hitting there, all is fine. Study firewall traffic through the network and note that the majority of incoming traffic (that was making it through to the network that is), was headed to the DNS servers. The attackers were sending the DDoS to the DNS servers, requesting some of our root domains and given that it appeared as valid traffic there was not much to be done to filter any of it. The easy solution in this case happened to be blocking all Chinese and Russian IP's for a couple days which mitigated enough of it to solve. After that, we stopped hosting our own DNS.

Moral of the story: DNS services are a great learning tool to use and PowerDNS is probably where you want to start, but at scale you may or may not want to actually run your own.



(Thanks for the links you provided to the front ends in your other comment).

Would like to point out that ddos is a ymmv item obviously for anyone scared off by the potential for this which is the same as the potential for any ddos attack and mitigation. A company affiliated with ours has been managing dns for a customer since 1996 with 10k zones. Back when you had to read Cricket Liu Oreilly book. (movie.edu if anyone remembers). They've never experienced a problem. All run on pretty low powered hardware for that matter.

That said there are things to know about dns while not difficult time could be better spent elsewhere if there is no compelling reason to diy.


DDoS risk is based on the type of business you're running (online casino, ecommerece, etc) and not really much to do with if you are running infrastructure in house or not.

For that matter, I don't know of a reputable DDoS mitigation service that doesn't provide DNS hosting as part of the package. It's pretty core to the whole thing.


Indeed, but what I was mostly getting at is that you have another possible attack vector if your run your own DNS, while services that provide it for you are basically pennies on the dollar compared to potential losses.


You'd be surprised how often your first assertion doesn't hold, actually.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: