It seems to me that he's saying in order to move data at volume, you have to compute on it.
Computation is tricky. Per-bit, if you can handle the network input, you're probably able to fire packets up to the OS layer.
But when you need to run stats on the incoming data, e.g. an ML classifier of "bad/not bad" or "stop/passthrough", you might be O(n^2) or worse. Moore's can't hang.
None, really. It's mostly filters against common types of attacks at L3/L4, then OODA. Variations from normal get looked at and custom filters applied as appropriate.
And of course, there's lots of NOC to NOC back channel comms around this stuff constantly to stay relatively on top of things.
Not sure if this applies to DDoS, but a baseline ML method for security is outlier detection. For example, (1) you get a dataset that is mostly "good" data, with some "bad" data (2) you cluster it using something fast like k-means (3) data points are labelled as outliers if they fall further than some threshold from a cluster center.
I think that's the secret sauce for these quys. I'd be surprised if you can find out a lot about current techniques without signing an NDA and leaving your mobile phone in a box at security.
Computation is tricky. Per-bit, if you can handle the network input, you're probably able to fire packets up to the OS layer.
But when you need to run stats on the incoming data, e.g. an ML classifier of "bad/not bad" or "stop/passthrough", you might be O(n^2) or worse. Moore's can't hang.