4 ms·
I think that effort would be better spent encouraging (see Forcing) ISPs to start dropping forged traffic at their borders. IMO there should be significant pen
by click170 11y ago
I think that effort would be better spent encouraging (see Forcing) ISPs to start dropping forged traffic at their borders.
IMO there should be significant penalties for network operators who do not drop obviously I forged traffic. How long has that rfc been around now and how little adoption has it seen?
- ryanlol 11y ago>I think that effort would be better spent encouraging (see Forcing) ISPs to start dropping forged traffic at their borders. The importance of spoofed traffic to attackers is greatly exaggerated, I could personally easily send 500+ Gbit (probably terabit) sized attacks by spending a couple of weeks building a router botnet. No need to spoof IPs and at that point diminishing returns would make amplification attacks useless. Not only that, but most amplified attacks are particularly inexpensive to filter. >IMO there should be significant penalties for network operators who do not drop obviously I forged traffic. How long has that rfc been around now and how little adoption has it seen? Who would penalize them? Why? And I'm not entirely sure if you understand what RFCs are, that RFC (which hasn't even been around for very long) is - most other RFCs - completely meaningless.
- cft 11y agoIn practice, most volumetric attacks have spoofed IPs- amplified UDP reflection attacks and even SYN floods with no amplification. Getting rid of UDP amplification reflection attacks will get rid of 90% of volumetric attacks.
- ryanlol 11y agoWe had volumetric attacks every day much before reflection attacks became common, the biggest attacks these days aren't reflected but from router nets. And you simply cannot solve IP spoofing without rebuilding the entire internet, not to mention the fact that it does have legitimate use cases. Also, if IP spoofing is making filtering difficult for you then you're doing filtering wrong.
- cft 11y agoHow big were the volumetric attacks that you saw that involved real IPs? The amplification factor is 1x for the real IPs. With NTP reflection and DNS reflection, you get 50x amplification, so 1Gbps botnet (trivial bandwidth) will cause a 50Gbps DDos (non-trivial bandwidth). This is why filtering is desirable.
- ryanlol 11y agoI saw a 500Mpps SYN flood just last week, followed by about 500Gbps of UDP packets. All from real IPs. Botnets have far surpassed amplification attacks at this point. >This is why filtering is desirable. Come up with a way to implement it that actually works and doesn't break legitimate use cases. spamsolutions.txt is starting to seem relevant here.
- cft 11y agoWe work with Verisign that specializes in DDoS mitigations, they have state of the art scrubbing centers on four continents and they are leading mitigation provider to the banks and schools. They told me they almost never see anything above 300gig. You must be special.
- ryanlol 11y agoYes, I would imagine I have far more experience dealing with large attacks than verisign. >they are leading mitigation provider to the banks and schools :)
- solotronics 11y agoWe are careful to operate by that security RFC and have BGP filters for every customer to prevent the possibility of spoofed traffic and DDoS originating from my network. It really is the responsibility of the network operators go be diligent in this. TWC - Business Class Fiber