[116479] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: DNS hardening, was Re: Dan Kaminsky

daemon@ATHENA.MIT.EDU (Roland Dobbins)
Wed Aug 5 14:31:00 2009

From: Roland Dobbins <rdobbins@arbor.net>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <4A79CB90.708@mail-abuse.org>
Date: Thu, 6 Aug 2009 01:31:55 +0700
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Aug 6, 2009, at 1:12 AM, Douglas Otis wrote:

> Having major providers support the SCTP option will mitigate  
> disruptions caused by DNS DDoS attacks using less resources.

Can you elaborate on this (or are you referring to removing the  
spoofing vector?)?

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>

         Unfortunately, inefficiency scales really well.

		   -- Kevin Lawton



home help back first fref pref prev next nref lref last post