nanog mailing list archives
Re: automatic rtbh trigger using flow data
From: "Roland Dobbins" <rdobbins () arbor net>
Date: Fri, 31 Aug 2018 22:32:01 +0700
On 31 Aug 2018, at 16:33, Ryan Hamel wrote:
From experience, sflows are horribly inaccurate for DDoS detection, since the volume could disrupt the control plane and render the process useless, thus not giving data to the external system to act upon it.
On the contrary, flow telemetry in general works quite well for DDoS detection/classification/traceback, and is widely utilized for such purposes; it has been for many years.
I'm not a big fan of s/Flow comparatively speaking, but it and NetFlow, IPFIX, et. al. have proven themselves over the years, assuming that the flow export parameters on the exporting devices are configured correctly, and the collection/analysis systems are configured optimally.
Flow telemetry is management-plane, not control-plane. Implementing network infrastructure self-protection BCPs such as iACLs is definitely recommended in general.
----------------------------------- Roland Dobbins <rdobbins () arbor net>
Current thread:
- Re: automatic rtbh trigger using flow data, (continued)
- Re: automatic rtbh trigger using flow data Joe Maimon (Aug 30)
- RE: automatic rtbh trigger using flow data Michel Py (Aug 30)
- Re: automatic rtbh trigger using flow data Aaron Gould (Aug 30)
- Re: automatic rtbh trigger using flow data Roland Dobbins (Aug 30)
- Re: automatic rtbh trigger using flow data Hugo Slabbert (Aug 31)
- Re: automatic rtbh trigger using flow data Roland Dobbins (Aug 31)
- Re: automatic rtbh trigger using flow data Joe Maimon (Aug 30)
- RE: automatic rtbh trigger using flow data Michel Py (Aug 30)
- Re: automatic rtbh trigger using flow data H I Baysal (Aug 31)
- RE: automatic rtbh trigger using flow data Ryan Hamel (Aug 31)
- Re: automatic rtbh trigger using flow data H I Baysal (Aug 31)
- Re: automatic rtbh trigger using flow data Roland Dobbins (Aug 31)
- RE: automatic rtbh trigger using flow data Michel Py (Aug 31)
- RE: automatic rtbh trigger using flow data Lotia, Pratik M (Aug 31)
- Re: automatic rtbh trigger using flow data Roland Dobbins (Aug 31)
- RE: automatic rtbh trigger using flow data Lotia, Pratik M (Aug 31)
- RE: automatic rtbh trigger using flow data Aaron Gould (Aug 31)
- Re: automatic rtbh trigger using flow data Hugo Slabbert (Aug 31)