15:03 < marita_RIPENCC> Wouter de Vries has begun the presentation "Scalable High-Speed Packet Capture using OpenFlow and Intel DPDK".
15:23 < marita_RIPENCC> Pavel Odintsov has begun the presentation "FastNetMon – Open Source DDoS Mitigation Toolkit".
15:26 < dnshane> UDP makes reflection (and amplification) attacks trivial. No surprise that most DDoS is UDP...
15:26 < Azi-47720> fastnetmon is quite useful
15:38 < dnshane> "Just download this Perl script and run it as root."
15:39 < job> i really like fastnetmon
15:39 < Azi-47720> with netmap it's lightning fast if somewhat CPU intensive
15:39 < job> here is another presentation about a fastnetmon deployment
15:40 < dnshane> Seems quite excellent.
15:40 < Azi-47720> default thresholds are a wee bit paranoid, that's about all the issues I've had
15:41 < dnshane> Presumably you dedicate a box for the task, so surely as long as the CPU keeps up with the traffic rate there is no problem?
15:42 < Azi-47720> with netmap it assigns one CPU per interface
15:43 < Azi-47720> I've not yet seen what it looks like at actual 10G of traffic
15:43 < Azi-47720> (per interface)
15:44 < Azi-47720> mind you, dropped/un-analysed packets should not necessarily be a problem with a DDoS
15:44 < dnshane> Right, the only failure mode is where your normal traffic is close to line rate, in which case you want more bandwidth anyway. 😛
15:45 < marita_RIPENCC> The NRO NC Candidates will now introduce themselves.
15:53 < marita_RIPENCC> Vicente De Luca has begun the presentation "Detecting and Mitigating DDoS: A FastNetMon Use Case”
16:05 < marita_RIPENCC> Thomas Weible has begun the presentation “The 101 of 100G Interoperability”
