>>What's their ip address? We could all ping them 10000 times as a group.
>
>The source is using a very smart application to hit the site. Once I block the related route, they start over with another route. And, that is done in the next second. So, it is being hit on a very slow interval. Then, if not being detected, the refresh interval is increased. Yesterday, again, I had to spend several hours to counter attack those attacks. I really do not know who is being this. But, this is starting to be very annoying. Today, we are still working on it.
Is there any unique pattern to the traffic that you can create a blackhole rule for?
Can you block large subnets of the general range of IP from which the traffic is coming?
They will stop eventually. There is little to gain.
In the End, we will remember not the words of our enemies, but the silence of our friends - Martin Luther King, Jr.