6 ms·
There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.
by codedokode 3y ago
There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.2.3.4/16.
But ISPs do not want to adopt such protocol.
- HumblyTossed 3y agoI am pretty sure that protocol would be just as abused.
- codedokode 3y agoHow exactly? You can authenticate sender by sending a special confirmation token back.
- sophacles 3y agoHow does one get removed from the block list? Say some IoT device that half of households own gets compromised and turned into a giant botnet. The news gets out and everyone throws away that device. Now they are still blocked over a threat that doesn't exist anymore... doesn't seem like a good situation for anyone. I'd imagine that the website owners that want the attack stopped will soon want to figure out how to get traffic back since they need users to pay the bills. Whats to stop someone from just making an app that participates in an attack when connected to public(ish) wifi networks and participating in attacks long enough to get those all shut off from major sites? How does this stop entire ISPs from getting shut off when the attackers have managed to cycle through all the IP pools used for natting connections? (e.g. the Comcasts of the world that use cg-nat to multiplex very large numbers of people to very small numbers of IPs)?
- grotorea 3y agoAs much as I half-wish there was something like this, it does sound like email spam blacklists all over again.
- codedokode 3y ago> How does one get removed from the block list? We can add an "accept" packet that lifts the ban. Also, how do you remove yourself from blacklist when banned by Google or Cloudflare? I guess here you use the same method. > Say some IoT device that half of households own gets compromised and turned into a giant botnet. The news gets out and everyone throws away that device. Now they are still blocked over a threat that doesn't exist anymore... doesn't seem like a good situation for anyone. Not my problem. Should have thought twice before buying a vulnerable device and helping criminals. As a solution they can buy a new IP address from their ISP.
- ilyt 3y agoWhat you say already exists, hell, you can use BGP to distribute ACLs But it costs space in the routing tables and that means replacing routers earlier. It's no wonder, especially if you multiply it by thousand customers. "block all traffic from outside from this IP" is significantly easier than "block all traffic from outside from this IP to this client". And you need to do it per ISP client, else it is ripe for abuse. And don't forget a lot of the traffic will come from "cloud" itself.
- codedokode 3y ago> What you say already exists, hell, you can use BGP to distribute ACLs But you should own an AS for that? > But it costs space in the routing tables Not implementing my proposal leaves critical infrastructure unprotected from foreign attacks. Make larger routing tables. Also, instead of blocking single IPs one can block /8 or /16 subnets.
- CountSessine 3y agoMake larger routing tables. Brilliant! Why didn’t we think of that?!? MOARE TCAMS!!!
- codedokode 3y agoif Cloudflare can do this on commodity hardware (stop attacks and block thousands of IPs), then router manufacturers who have custom hardware can do much more. Also, in Russia for example, there is DPI inspection and recording of all Internet traffic and if it is possible in Russia, then West can probably do 10x more. Simply adding a blacklist on routers seems like an easy task compared to DPI inspection.
- codedokode 3y agoThis can be made on a paid basis. For example, for $1/month a customer gets a right to insert 1000 records (block up to 1000 networks or IPs) into blacklist on all Tier-1 ISPs. For $100/mo you can withstand an attack from 100 000 IPs which is more than enough and Cloudflare goes bankrupt.
- tsimionescu 3y agoSo I can deny service to your site with a single packet, instead of having to bother with establishing a whole botnet? The current botnet customers would be the first to advocate for this new protocol!
- alexfoo 3y agoSimple! To prevent it being abused easily you could make it so you would need to send a high number of those packets for a sustained period in order to activate the block.
- simondotau 3y agoAnd there could be a short time limit on that block, perhaps one hour, but even 60 seconds would be enough to completely flip the script on a DDoS.
- codedokode 3y agoYou can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't require any lists like Spamhaus that have vague policies for inclusion and charge money for removing. My proposal doesn't have any potential for misuse.
- ComodoHacker 3y agoHow can it protect from... botnets, where there are tens of thousands "someones"?
- codedokode 3y agoYou can only ban packets coming to your IP. Botnet can only ban packets coming to its IP addresses.
- plagiarist 3y agoSorry, this is not well-thought and certainly has potential for abuse. This is on IP and not domain? What is the signing authority and cryptography mechanism preventing a spoofed request?
- 6510 3y agoI just imagined this: isp's could make a isp.com?target=yourwebsite.org/fromisp [slow] redirecting url. If you receive unusual amounts of requests from the isp you redirect it though their website. They can then ignore it until their server melts (which takes care of the problem) or take honorable action if one of their customers is compromised. The S stands for service after all.
- oefrha 3y agoIt appears you don’t understand DDoS at all. There aren’t humans sitting behind browsers or scripts using browser automation software. No one cares about less respects your “redirect” because no one’s reading your response. Most of the time the attacks aren’t even HTTP, they are just packet floods.
- 6510 3y ago> It appears you don’t understand DDoS at all. I can confirm this. I see web pages talking about redirecting traffic to scrubbing centers.
- rootlocus 3y ago> Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.2.3.4/16. So, if my neighbour is infected and one of his devices is part of a botnet, I get blocked as well?
- bee_rider 3y agoBlock the whole country, then I guess you’ll see laws passed that IOT providers need to start updating at a better clip.
- rcxdude 3y agoThat already effectively happens in a lot of cases.
- codedokode 3y agoYes. Because blocking several extra users on a bad network that has several infected hosts and does nothing about it is better than being under attack.
- eptcyka 3y agoDo you know what the first D in DDoS attack stands for?
- toast0 3y agoIf the source field in a packet reliably indicated the source of the packet and a given IP was sending you a lot of unwanted traffic, you'd ask their ISP to turn them off and the problem would be solved. Maybe one day BCP38 will be fully deployed and that will work. I also dream of a day where chargen servers are only a memory. Some newer protocols are designed to limit the potential of reflected responses. Null routing is available in some situations, but of course it's not very specific: hey upstreams (and maybe their upstreams), drop all packets to my specific IP. My understanding is null routing is often done via BGP, so all the things (nice and not) that come with that. Asking for deeper packet inspection than looking at the destination is asking for router ASICs to change their programing; it's unlikely to happen. Anyway, the distributed nature of DDoS means you'd need hundreds of thousands of rules, and nobody will be willing to add that. Null routing is effective, but of course it takes you IP offline. Often real traffic can be encouraged to move faster than attack traffic. Otherwise, the only solution is to have more input bandwidth than the attack and suck it up. Content networks are in a great position here, because they deliver a lot of traffic over symetric connections, they have a lot of spare inbound capacity.
- codedokode 3y ago> If the source field in a packet reliably indicated the source of the packet and a given IP was sending you a lot of unwanted traffic, you'd ask their ISP to turn them off and the problem would be solved No. Your email will go straight into trash because ISP is not interested in doing something for people who don't pay them money. Also, even if they cooperate, it will take too much time. > Null routing is available Null routing means complying with criminals' demand (they want the site to become inaccessible). > it's unlikely to happen It will very likely happen if there will be a serious attack on Western infrastructure: for example, if there will be no electricity in a large city for several days, of if hospitals across the country won't work or something like this. Then the measures will be taken. Of course, while the victims are small non-critical businesses, nobody will care. > Otherwise, the only solution is to have more input bandwidth than the attack and suck it up. Content networks are in a great position here, because they deliver a lot of traffic over symetric connections, they have a lot of spare inbound capacity. So until my proposal is implemented the only solution is to pay protection money to unnecessary middlemen like Cloudflare.