4 ms·
> The main reason DDOS attacks exist is poor security and lack of cooperation between ISPs. Lack of adequate security on desktops (usually Windows) makes it pos
by devicenull 11y ago
> The main reason DDOS attacks exist is poor security and lack of cooperation between ISPs. Lack of adequate security on desktops (usually Windows) makes it possible to build large bot networks.
These days it's the hundreds of thousands of misconfigured NTP servers, recursive DNS servers, and various other protocols being abused for reflection attacks.
Granted, it still requires that the attacker have the ability to spoof packets, but preventing that requires even more time investment and has very little benefit to the ISP.
- jsmthrowaway 11y agoBCP 38 is like herd immunity with immunization, and much like anti-vaccine folks, networks that don't follow it are knowingly choosing to infect people for any number of reasons. Despite your claim, it is extremely easy to implement and has been a known best practice, with accompanying educational Web sites devoted to the topic[0], for many years. There are nearly zero reasons for your AS to transmit forged packets, and if your configuration allows it, you are knowingly making the Internet a worse place with your laziness and transferring your laziness to other people like me that carry pagers. This isn't a surprise to any network administrator unless they've spent their entire career not reading RFCs. I'm of the opinion that networks that allow customers to emit forged source addresses should be depeered until they take the literal hour to fix it. "But we have to update equipment when we get new blocks!" Boo hoo. Automate it or get off the Internet so I can stop spending my life dealing with your customer's amplified traffic. If you run a non-transit/eyeball AS, you are in the absolute best position to stop these types of attacks from ever happening. The rest of the Internet, particularly your transit peers, can't really clean up after you on this one. Do us all a favor. [0]: http://bcp38.info http://bcp38.info
- devicenull 11y agoI'd argue that the end networks really aren't the best place to be implementing this. If the big transit providers (Level3, NTT, etc) started enforcing it, it would significantly reduce the effectiveness of spoofed traffic pretty much overnight.
- jsmthrowaway 11y agoIt might seem that way, but they can't scale that, as you might know. It's tougher for DFZ transit to do it because they must know, and programmatically configure, all downstream space to be whitelisted. Now you have a similar conversation to BGP filtering when downstream networks change space, and that's huge administrative overhead (which is why announcements are just trusted without filtering at the higher levels, to avoid this overhead for the larger AS). Your end network is a better place because you know your assigned space better, as well as how you number it; you might be holding half an /18 and not assigning it, whereas your peer would whitelist it all, for example. If the technicals of the Internet were programmatically available in a sane way (PeeringDB doesn't count here, since it just automates manual work), the Tier 1s could potentially automate against their downstream AS' space and enable your (mostly correct) point. However, we pretty much fly blind in this respect and rely on emails and ticketing and decentralized systems to manage the control plane of the Internet. Which honestly continues to shock me, even though it makes sense since the Internet is designed as "decentralized" despite being anything but in usage. Edit: While in the car, I realized that Paul Vixie's paper on this discusses the CPE source-filtering angle in great detail, which might illustrate my opinion a little better for you than I ever could: https://queue.acm.org/detail.cfm?id=2578510 https://queue.acm.org/detail.cfm?id=2578510
- secstate 11y agoGiven my ignorance of much of these issues, I probably shouldn't be commenting (take my comment with a huge grain of salt). But the idea of depeering networks on the Internet for misapplication of a voluntary protocol seems like the beginning of the end of a free Internet (if ever such a thing existed). If BCP38 is critical to the success of the Internet, I think rather than ranting about those not implementing it, energy would be better spent petitioning to have it made a requirement of running a peer on the Internet to begin with. Perhaps I'm off base or starting some sort of network guru flamewar. If that's the case, down vote me and I'll go away ;)
- akerl_ 11y agoTo be clear: having the networks that make up the internet agree to depeer networks that don't implement a protocol is roughly the same as "making it a requirement", and the petitioning you'd need to do is "convince all the networks to agree to do it". Because the internet is "free", more or less, there isn't much in the way of enforcement of which RFCs and practices must be followed to be part of it, which is a big part of the reason that BCP38 is so underutilized today.
- jsmthrowaway 11y agoYour heart's in the right place, but the Internet is built on policies of individual networks because there is nobody to enforce. Your suggestion back to me is simply mine in different clothing, because you think someone can enforce such a global requirement. Enforcing policy like "filter or get depeered" is the only way to achieve a global requirement like you want with the way the Internet is structured. As akerl points out you need consensus, too, because such a policy could drive customers to other networks upon enforcement, which is a business disincentive to do it. It's kind of a surprising moment when you realize what the Internet is and how little structure it has aside from the protocols themselves. We are one global Internet (semi) outage away from rethinking some of this structure, and I expect one in my lifetime.
- secstate 11y agoThanks for the kid-gloves reply :) I hadn't considered that there isn't really a central authority for controlling who runs a peer, aside from ICANN, but they have pretty loose reins. Funny that everyone waxes poetic about bitcoin being a revolution in anonymous and tacit network management. Meanwhile our little Internet experiment continues to be a HUGE tacit agreement to adhere to a handful of network protocols.