4 ms·
Ok, dumb question: Why can't a list of addresses of all the devices in the world of the type used in the attack be created, and all packets from any address on
by marze 10y ago
Ok, dumb question:
Why can't a list of addresses of all the devices in the world of the type used in the attack be created, and all packets from any address on the list be trashed? At least, for the duration of the attack.
If such lists were made ahead of time, they could be turned on rapidly.
Is anything like this done?
- hueving 10y agoTwo issues: NAT and dynamic addresses. NAT: blocking an iot address may be blocking grandma's whole network (or her whole apartment complex's network), and the ISP doesn't want that support call. Dynamic addresses: depending on the ISP, the IP could change quite frequently (daily), so keeping the list up to date to avoid collateral damage to the unlucky recipient of the blacklisted IP is very difficult.
- 1812calif 10y agoYou are speaking of basically an IP-based version of the spamhaus blacklist. For general http or TCP protocol. I, for one, would be fine with a general internet citizen losing access if they have a compromised device. I suspect this is how we will go -- your home security cam was used in an attack, now every single website you visit for XXXXXXXX days gives you a CAPTCHA. I maintain the crucial element is informing people why they have that hassle. Add extra friction, but not inhibit what they can do, because they are unable and unwilling to secure their devices. Yes, this affects the internet-uneducated disproportionately. Yes, I think it is the responsibility of anyone with a broadband connection to understand the responsibilities that come with it. No, I do not expect grandma to learn this. I expect her to deal with a crippled internet because they are not able to fix their pollution.
- michilehr 10y agoIn germany, the Telekom (T-Online) used to block http or SMTP traffic when they recognized an infected connection which sent SPAM emails. Don't know if they still act like this.
- rasz_pl 10y agoL3 already confessed to having build a list of >500K Mirai bot static IPs, they used it to .... do NOTHING, because they are in business of selling pipes, and ddos makes good business.