Today several financial institutes in Israel (banks, stock exchange) were DDOSed. They decided to block all foreign IPs as a first aid measure.
While I agree that it was possibly the best thing to do as a first aid measure, I was really surprised it was necessary. Don't banks and large institutes like the Tel Aviv Stock Exchange have "serious enough" DDOS protection?
How much it would cost to implement protection against DDOS attacks? I know there are ranges of possible DDOS attacks, from silling SYN attacks to more serious application level DDOS. I'm interested in how much would it cost to protect against each of these (just trying to understand why it wasn't implemented well in advance in this case).