@Clive Robinson
The problem with asymetric attacks is as I keep noting "attribution is hard" and the fact you are being attacked by traffic from country A does not mean it has not come through a number of other countries from country G.
Doesn't matter. I'm not paid to police A's network, nor any connection leading back to G. If I can cut off A at the firewall without serious collateral damage (i.e., nobody there is buying our stuff and we're not buying theirs), I'm going to do that to stop the attacks. The onus is on A to get their security in order if they want a seat on the world stage.
That is if even the most Internet sophisticated country America can not stop malware and other cyber-crime code, how the heck do we expect any other nation to do so?
Are you joking? The US is nowhere near implementing best practices when it comes to these matters. Look no further than the cloud providers who will sell their services to anyone with a couple of bucks. When a "customer" pays Amazon for the use of a server, Amazon doesn't do jack to vet them, or monitor their traffic. If they attack me, Amazon doesn't reward me for reporting them or compensate me for any damage done. The profit motive here makes America one of the least Internet sophisticated countries when it comes to dealing with abuse. France is no better, of course. They are on my list of countries that, when attacked by a single server there, the firewall gets an entry for not just that server or the providers network, but the largest CIDR managed within the country. If they want people to take their stance on cyberwarfare seriously, they need to do a better job of stopping the attacks already being launched from their own territories. baeeb75459f15909d8d9f336fb11640c745ab111c5ccf97ed62a370fc36f9f2f