- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,428
FSTEC for the first time explains the protection not through regulatory turnover, but through SYN cookies and Nginx timeouts, which significantly surprises engineers.

FSTEC of Russia has published recommendations on the protection of information infrastructure from attacks such as “reservation”. The document came out against the background of the growth of DDoS attacks on Russian networks and is addressed not only to government agencies, but also to operators of state information systems, subjects of critical information infrastructure, telecom operators and owners of information and telecommunication networks.
The agency describes the defense not in general phrases, but through specific classes of attacks. The document includes measures against overloading communication channels, including UDP-flud, ICMP-flud, DNS and NTP-ampification, against protocol attacks like SYN-Flude and fragmentation attacks, as well as against attacks at the application level, including HTTP-floods, Slowloris and slow POST queries. A separate unit is dedicated to multi-vector attacks, where attackers simultaneously hit several levels of infrastructure.
The recommendations look like an engineering memo for network administrators and information security specialists. FSTEC proposes to conduct an inventory of services available from the Internet, divide critical resources at different IP addresses or subnets, configure traffic monitoring and record normal load values in advance. For such monitoring, the document mentions NetFlow, sFlow, IPFIX, as well as open tools like Zabbix, LibreNMS and tentong.
Special attention was paid to the regulator by telecom operators. To protect against the substitution of IP addresses, FSTEC recommends including a check of the uRPF back path on subscriber interfaces, and to respond to major attacks, use BGP Remote Triggered Black Hole and interact with traffic cleaners through BGP sessions, IPsec or GRE tunnels. If the attack is detected, organizations are offered to immediately connect the specialists of the telecom operator, and not to try to reflect the overload only by means of their own site.
In the technical part, the document touches on routers, firewalls, servers and Linux systems. For UDP-Fluda, FSTEC recommends limiting the speed of traffic on network devices and disable unused UDP services. For ICMP-Flude - to prohibit broadcast ICMP queries and leave only the necessary service protocols. For SYN-Fall – enable SYN cookies, apply stateful inspection and limit the number of semi-open connections.
To attack web applications, the agency proposes to use WAF, antiboth protection through reverse proxy or load balancers, block empty and suspicious User-Agent, and configure connect timeouts so that slow requests do not hold server resources for too long. The recommendations also mention Nginx settings, including limiting the size of the header and the query body.
The publication of FSTEC lies in the general trend of the beginning of 2026. According to market participants, attackers are more likely to combine several methods in one incident, and the load shifts between the telecom, the public sector, industry and commercial services. In the first quarter of 2026, the share of attacks on industry, according to Garda, increased from 8% to 19%, and the telecommunications sector retained the largest share of attacks, although it decreased from 43% to 32%.
The new document does not introduce a separate regulatory regime, but shows what set of practical measures FSTEC considers the basis for protection against DDoS. For organizations, the meaning of the recommendations comes down to a simple thing: protection against denial of service is no longer limited to buying one filtration service. The infrastructure needs to be described in advance, divided, configured, tied to monitoring and agree on the procedure with the telecom operator before the attack.

FSTEC of Russia has published recommendations on the protection of information infrastructure from attacks such as “reservation”. The document came out against the background of the growth of DDoS attacks on Russian networks and is addressed not only to government agencies, but also to operators of state information systems, subjects of critical information infrastructure, telecom operators and owners of information and telecommunication networks.
The agency describes the defense not in general phrases, but through specific classes of attacks. The document includes measures against overloading communication channels, including UDP-flud, ICMP-flud, DNS and NTP-ampification, against protocol attacks like SYN-Flude and fragmentation attacks, as well as against attacks at the application level, including HTTP-floods, Slowloris and slow POST queries. A separate unit is dedicated to multi-vector attacks, where attackers simultaneously hit several levels of infrastructure.
The recommendations look like an engineering memo for network administrators and information security specialists. FSTEC proposes to conduct an inventory of services available from the Internet, divide critical resources at different IP addresses or subnets, configure traffic monitoring and record normal load values in advance. For such monitoring, the document mentions NetFlow, sFlow, IPFIX, as well as open tools like Zabbix, LibreNMS and tentong.
Special attention was paid to the regulator by telecom operators. To protect against the substitution of IP addresses, FSTEC recommends including a check of the uRPF back path on subscriber interfaces, and to respond to major attacks, use BGP Remote Triggered Black Hole and interact with traffic cleaners through BGP sessions, IPsec or GRE tunnels. If the attack is detected, organizations are offered to immediately connect the specialists of the telecom operator, and not to try to reflect the overload only by means of their own site.
In the technical part, the document touches on routers, firewalls, servers and Linux systems. For UDP-Fluda, FSTEC recommends limiting the speed of traffic on network devices and disable unused UDP services. For ICMP-Flude - to prohibit broadcast ICMP queries and leave only the necessary service protocols. For SYN-Fall – enable SYN cookies, apply stateful inspection and limit the number of semi-open connections.
To attack web applications, the agency proposes to use WAF, antiboth protection through reverse proxy or load balancers, block empty and suspicious User-Agent, and configure connect timeouts so that slow requests do not hold server resources for too long. The recommendations also mention Nginx settings, including limiting the size of the header and the query body.
The publication of FSTEC lies in the general trend of the beginning of 2026. According to market participants, attackers are more likely to combine several methods in one incident, and the load shifts between the telecom, the public sector, industry and commercial services. In the first quarter of 2026, the share of attacks on industry, according to Garda, increased from 8% to 19%, and the telecommunications sector retained the largest share of attacks, although it decreased from 43% to 32%.
The new document does not introduce a separate regulatory regime, but shows what set of practical measures FSTEC considers the basis for protection against DDoS. For organizations, the meaning of the recommendations comes down to a simple thing: protection against denial of service is no longer limited to buying one filtration service. The infrastructure needs to be described in advance, divided, configured, tied to monitoring and agree on the procedure with the telecom operator before the attack.