nanog mailing list archives

Re: SP 800-189 (Draft), Resilient Interdomain Traffic Exchange


From: Job Snijders <job () ntt net>
Date: Mon, 28 Oct 2019 16:09:54 -0500

Dear Douglas,

Thanks for sharing the link. This is an impressive effort!

Can you share with the group what the best way is to share feedback to
effect changes in the document?

Is there a difference between just emailing you or are there official
channels to be considered?

Kind regards,

Job

On Mon, Oct 28, 2019 at 16:04 Montgomery, Douglas C. (Fed) via NANOG <
nanog () nanog org> wrote:

https://csrc.nist.gov/publications/detail/sp/800-189/draft





/



This document provides technical guidance and recommendations for
technologies that improve the security and robustness of interdomain
traffic exchange. Technologies recommended in this document for securing
the interdomain routing control traffic include Resource Public Key
Infrastructure (RPKI), BGP origin validation (BGP-OV), and prefix
filtering. Additionally, technologies recommended for mitigating DoS and
DDoS attacks include prevention of IP address spoofing using source address
validation with access control lists (ACLs) and unicast Reverse Path
Forwarding (uRPF). Other technologies such as remotely triggered black hole
(RTBH) filtering, flow specification (Flowspec), and response rate limiting
(RRL) are also recommended as part of the overall security mechanisms.



dougm

--

Doug Montgomery, Manager Internet  & Scalable Systems Research @ NIST




Current thread: