How should provider mitigation records be used?¶
The practical answer¶
Provider and mitigation-service records may be central to understanding a denial-of-service incident.
The key evidential caution¶
The dangerous assumption is that the organisation’s own logs contain the full attack picture.
Traffic may be blocked upstream before it reaches the target.
Providers may hold:
Key points¶
- attack start and end times
- traffic volume
- protocol breakdown
- source distribution
- filtered packets
- mitigation rules
- scrubbing-centre records
- service-health data
- alerts
- incident summaries
Evidence to preserve¶
Investigators should preserve native exports and the provider’s explanation of how measurements were produced.
A provider summary may be useful but may combine, sample or classify traffic using product-specific logic.
Obtain the underlying detail where proportionate.
Evidential limits¶
Do not assume provider labels such as “DDoS attack” prove offender identity or malicious intent without supporting events.
Also record when mitigation began, because filtered traffic may change what later logs show.
Provider retention may be limited, making early preservation important.
Where the provider applied automated mitigation, preserve the rule, threshold and activation time. The organisation may see recovery while attack traffic continues upstream. Conversely, mitigation itself may block legitimate users, so service impact should be separated from attack volume and defensive filtering.
Provider classifications may also change as analysis improves. Preserve the original alert, later incident report and any explanation of revised estimates. Differences in sampling, aggregation or scrubbing may produce apparently inconsistent traffic figures without either record being false.
Where the provider only supplies a narrative summary, record the limitation and seek the underlying time range, traffic type and affected resource. A concise incident label may be operationally useful but insufficient for precise evidential conclusions.
Operational takeaway¶
Use provider records to reconstruct upstream traffic and mitigation, and understand the measurement and classification limits before relying on summary labels.