3 ms·
Yeah, it seems like it should be possible to send a packet using a "firewall rule protocol" to the DoSing IP address, and have any non-malicious routers in betw
by devit 9y ago
Yeah, it seems like it should be possible to send a packet using a "firewall rule protocol" to the DoSing IP address, and have any non-malicious routers in between enact a rule that blocks traffic in the opposite direction (obviously there needs to be either spoofing prevention, or the packet must be signed with a certificate provided by the RIR to prove ownership of the source IP address).
Why not do this? Is it impossible to design it in a non-abusable way, or is there too much overhead to store and apply a possibly long list of arbitrary blocking rules?
- mjevans 9y agoWell, there would be the overhead, so more ideally you'd be submitting such requests to an out of band network (possibly forward to such a CnC network /by/ the routers along the way). The command and control network would authenticate the source request via some means and if it's authentic act accordingly. The benefit of this is that it also allows for identifying infected or otherwise abusive customers and actually being proactive about getting them cleaned up. Of course all of that degrades the 'customer' experience, and costs money. Both of which are probably why no one does this right now.
- zzzcpan 9y agoISPs do this and have such capabilities. They don't necessarily use the same protocol, like BGP Flow Specification (RFC 5575), but they often do provide a way to push filtering rules if you need it and you are an ISP yourself.