nanog mailing list archives

Re: Real-Time Mitigation of Denial of Service Attacks Now Available With AT&T


From: Valdis.Kletnieks () vt edu
Date: Wed, 02 Jun 2004 15:26:28 -0400

On Wed, 02 Jun 2004 11:39:39 MDT, Danny McPherson <danny () tcb net>  said:

How do you discriminate *DDOS attacks employing source address spoofing*
from broken NATs, rampant worms, PMTU and other related misconfiguration
resulting in backscatter and similar garbage - with filter counters?  

A bogon packet is a bogon packet Filter them all and let the appropriate deity
sort them out (unless you bill by traffic volume ;)

Attachment: _bin
Description:


Current thread: