How should provider mitigation records be used?¶
Provider records may contain the clearest view of denial-of-service traffic blocked upstream. Use native data to reconstruct the event, while understanding how the service sampled, aggregated and classified it.
Preserve measurement and mitigation context¶
Obtain start and end times, volume, protocols, source distribution, filtered traffic, scrubbing data, service health, rules, thresholds and activation times. Record where measurements were taken and how estimates were produced.
Automated mitigation can restore local service while hostile traffic continues upstream. It can also block legitimate users, so attack volume, defensive filtering and user impact need separate timelines.
Treat summaries as interpretations¶
A provider label such as DDoS does not identify an offender or automatically prove intent. Preserve original alerts, later incident reports and explanations for revised figures or classifications.
Sampling and different observation points can produce inconsistent-looking totals without either being false. If only a narrative is available, document that limit and seek the underlying time range, traffic type and affected resource before making precise conclusions.
Key takeaway
Use provider records to recover upstream traffic and mitigation, but preserve the measurement method and distinguish provider classification, service effect and attribution.