3 ms·
I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any t
by codedokode 3y ago
I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any traffic from 2.2.2.2 to 1.1.1.1. This is very easy but very efficient and allows a single host to withstand the attack of any size.
There is no need for any central authority and no need to maintain any lists.
- Swenrekcah 3y agoThat actually sounds like a really good idea. This is already implemented in the physical world (in a much less efficient way) in the form of “no spam” stickers and registrations. Is there a reason other than inertia for why it hasn’t been implemented?
- codedokode 3y agoISPs do not want to spend money for fighting against criminals.
- Swenrekcah 3y agoThat doesn’t sound convincing to me. I mean I understand they don’t want to spend money but if cost is the only barrier it seems like that could be overcome somehow by interested parties.
- bombcar 3y agoIt's not the costs, it's that some ISPs like getting money from spammers and criminals, and carefully look the other way. And the other ISPs like getting paid for DDoS mitigation, so they also look the other way. There's no money to be made fixing the underlying problem.
- bombcar 3y agoThe main problem is how do you authenticate the request as being legitimate? It's already possible to spoof headers and "FROM-IP" (in fact, major DDoS attacks use just this as a replay attack, spoof a DNS request as coming from 1.1.1.1 and get a much larger response sent TO 1.1.1.1 from wherever).
- codedokode 3y agoYou can send back a reply with a token to confirm ban.
- KomoD 3y agoAnd then that can be abused...
- codedokode 3y agoNo, it cannot. It is well-thought.
- TheDong 3y agoThere are 2^128 ipv6 addresses. If you store 1 bit (banned/unbanned) + a unix timestamp (ban expiration) for each of those IPs, that requires more storage space than exists many billion times over. To store such a block table you propose would require more memory for routers than any router has ever had and ever will have. An attacker could easily "flush" all entries in this table by, for example, banning a TB of ipv6 addresses from talking to them, surely resulting in all participating routers dropping other bans to store some of those.
- codedokode 3y ago> An attacker could easily "flush" all entries in this table by, for example, banning a TB of ipv6 addresses We can set a limit of ban records per host to prevent it.
- codedokode 3y agoWe can store an IP address with a mask (ban subnets instead of separate addresses). Also, IPv6 is so rarely used, that I would ban whole address space for the time of attack. For example, if an attack is coming from a country you where you don't have many paying customers, but where there are many infected devices due to use of pirated outdated software, it is easier to ban the whole country than to figure out who is infected and who is not.
- sgjohnson 3y agoban the entire /64. If banning the /64 is not enough, then ban the /48. If that is not enough, keep going up 4 bits until it is (most IPv6 allocations line up on a nibble boundary, hence the 4 bits)