nanog mailing list archives

Re: Defeating DoS Attacks Through Accountability


From: bmanning () vacation karoshi com
Date: Sat, 11 Nov 2000 22:26:41 +0000 (UCT)


I'll put it this way: filtering should be done against blocks that a
customer can announce, not against blocks that a customer is actively
announcing.  If you're filtering purely against current advertisements,
you're bound to break something sooner or later.

Good theory. But what one public source do all the ISP agree to validate the
authority to announce?

Barry

        Seems that the closest thing available today is the in-addr tree.
        
--bill



Current thread: