Thanks for following up, and for publishing two bits of key data:
- This was part of a larger attack campaign that included CLDAP amplification
- The SYN/ACK amplification resulted in 208Mpps (or more)
Some additional questions, if you're able to answer them (off-list is fine if there are things that can't be shared broadly):
- How large was the CLDAP amplification attack? What was the packet rate of the initial fragments?
- The post suggested that the 208Mpps saturated some links. Did it cause other problems as well?
- Was the attack referred to law enforcement?
- Were any transit providers asked to trace the source of the spoofing to either stop the attack or facilitate the law enforcement investigation?
Damian