I don't know if this would work, but...

When a server is under DDOS attack it should redirecting each access request
to a page designed to authenticate a human user. This page would have a
basic layout (with a very small size):
Site URL

The server which hosts this site is currently under DDOS attack. To protect
against this, you need to be authenticated as a human being by typing the
following Turing number:

Turing number ______________ Type here ______________

Note that the navigation of the site will be slower than usual.

This way, the server would know that a specific IP address is used by a
human being, and thus allow it to access the original URL. The IP address is
allowed access for the next hour, after which time a new Turing number is
requested from the user to type.

Since the attacker could try this and obtain a valid IP address to use for
the attack, while the server is under attack it should monitor how fast
valid IPs try to access the server. If the access is to fast (compared with
the normal behavior of a human being), the server could block that IP.

George Hara


