Skip to content
CIM-206 Cyber Incidents & Offender Methods

How should provider mitigation records be used?

The practical answer

Provider and mitigation-service records may be central to understanding a denial-of-service incident.

The key evidential caution

The dangerous assumption is that the organisation’s own logs contain the full attack picture.

Traffic may be blocked upstream before it reaches the target.

Providers may hold:

Key points

  • attack start and end times
  • traffic volume
  • protocol breakdown
  • source distribution
  • filtered packets
  • mitigation rules
  • scrubbing-centre records
  • service-health data
  • alerts
  • incident summaries

Evidence to preserve

Investigators should preserve native exports and the provider’s explanation of how measurements were produced.

A provider summary may be useful but may combine, sample or classify traffic using product-specific logic.

Obtain the underlying detail where proportionate.

Evidential limits

Do not assume provider labels such as “DDoS attack” prove offender identity or malicious intent without supporting events.

Also record when mitigation began, because filtered traffic may change what later logs show.

Provider retention may be limited, making early preservation important.

Where the provider applied automated mitigation, preserve the rule, threshold and activation time. The organisation may see recovery while attack traffic continues upstream. Conversely, mitigation itself may block legitimate users, so service impact should be separated from attack volume and defensive filtering.

Provider classifications may also change as analysis improves. Preserve the original alert, later incident report and any explanation of revised estimates. Differences in sampling, aggregation or scrubbing may produce apparently inconsistent traffic figures without either record being false.

Where the provider only supplies a narrative summary, record the limitation and seek the underlying time range, traffic type and affected resource. A concise incident label may be operationally useful but insufficient for precise evidential conclusions.

Operational takeaway

Use provider records to reconstruct upstream traffic and mitigation, and understand the measurement and classification limits before relying on summary labels.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.