On 26 Feb 2016, at 10:52, Paras Jha wrote:
You don't typically see DNS amplified floods coming from home ISPs.
Actually, it's quite common, as a lot of CPE have abusable DNS forwarders running on their public interfaces.
DNS, SSDP, and SNMP reflection/amplification quite commonly emanate from broadband access networks due to abusable CPE. Others, as well, of course, but those are generally the most prevalent.
----------------------------------- Roland Dobbins <rdobb...@arbor.net>