3 ms·
No, it cannot. It is well-thought.
by codedokode 3y ago
No, it cannot. It is well-thought.
- TheDong 3y agoThere are 2^128 ipv6 addresses. If you store 1 bit (banned/unbanned) + a unix timestamp (ban expiration) for each of those IPs, that requires more storage space than exists many billion times over. To store such a block table you propose would require more memory for routers than any router has ever had and ever will have. An attacker could easily "flush" all entries in this table by, for example, banning a TB of ipv6 addresses from talking to them, surely resulting in all participating routers dropping other bans to store some of those.
- codedokode 3y ago> An attacker could easily "flush" all entries in this table by, for example, banning a TB of ipv6 addresses We can set a limit of ban records per host to prevent it.
- codedokode 3y agoWe can store an IP address with a mask (ban subnets instead of separate addresses). Also, IPv6 is so rarely used, that I would ban whole address space for the time of attack. For example, if an attack is coming from a country you where you don't have many paying customers, but where there are many infected devices due to use of pirated outdated software, it is easier to ban the whole country than to figure out who is infected and who is not.
- sgjohnson 3y agoban the entire /64. If banning the /64 is not enough, then ban the /48. If that is not enough, keep going up 4 bits until it is (most IPv6 allocations line up on a nibble boundary, hence the 4 bits)