Field Notes

Notes on security, networks, and programming.

Analysis, field reports, and practical tips to strengthen your IT skills.

https://mdriss.com/
Published 3 days ago 3 mins read

Post-Mortem: Anatomy of a DNS Amplification Attack on one of our public server.

You're settling in with a fresh cup of coffee, and suddenly your NOC monitoring screen turns as bright red as an emergency flare. A single server whose public IP address was unfortunately a little too well-known across the internet just became the target of a massive DNS Amplification DDoS Attack. As an Internet Service Provider (ISP), we see our fair share of weird traffic. But watching a single host get flooded with a 10 Gigabit wall of uninvited DNS answers is a classic scenario that goes from "interesting textbook theory" to "all-hands-on-deck emergency" in about four seconds flat.
Continue reading
https://mdriss.com/
Published 2 months ago 4 mins read

Why Traditional Network Monitoring Is Becoming Obsolete

After several years of monitoring and operating ISP infrastructures, I realized that we spend far more time interpreting data than collecting it. Between Centreon alerts, MRTG graphs, and vendor-specific management platforms, we have access to an enormous amount of information, yet we rarely achieve a true understanding of how our networks behave. This article explores the limitations of traditional monitoring and introduces a new vision: networks capable of building operational memory and learning from their own incidents.
Continue reading