>>105858720An actual DDoS happens on the transport layer (like a SYN-flood). Only an iptables DROP filter can save you there.
And if it is massive enough, the ISP of your datacenter has to blackhole you temporarily, to protect his service for other customers. Nothing you can do can save you there.
I personally experienced this three times by now.
The thing is, this is expensive. And they never run those for long, because they don't want their zombies in their botnet to be discovered.
So you pay lots of shekels, and get one ddos to kick kiwifarms off the internet for an hour?
Who the fuck cares! Just ignore it and wait it out!
Spaming http requests, while using far less zombies, however, is sustainable. You can do that indefinitely. Doesn't cost much and ISPs won't be bothered by it.
The POW will protect you against those.
Specifically:
Not the PoW, BUT the requirement to execute JavaScript before you can enter! You could just require them to execute randomly generated WebAssembly, and it would work just as well.