I assume the DDOS is not a generic flood of traffic, but rather a particular kind of traffic that causes a disproportionate ammount of work (or, rather, memory usage) in the target. In this case, the offending component would necessarily be part of the unencrypted portion of a TOR packet that the relay is processing.
2 comments
[ 4.3 ms ] story [ 84.5 ms ] thread