nanog mailing list archives

Re: Real-Time Mitigation of Denial of Service Attacks Now Available With AT&T


From: "Andrew - Supernews" <andrew () supernews net>
Date: Wed, 02 Jun 2004 16:53:56 +0100


"Jon" == Jon R Kibler <Jon.Kibler () aset com> writes:

 Jon> The sad fact is that simple ingress and egress filtering would
 Jon> eliminate the majority of bogus traffic on the Internet --
 Jon> including (D)DoS attacks. If all ISPs would simply drop all
 Jon> outbound packets whose source address is not a valid IP for the
 Jon> subnet of origin, and all inbound packets that do not have valid
 Jon> source IP addresses, the DDoS problem would be (for all intents
 Jon> and purposes) fixed.

The majority of the DDoS traffic that's been received here over the
past year has had 100% valid and accurate source IP addresses.

-- 
Andrew, Supernews
http://www.supernews.com


Current thread: