[116479] in North American Network Operators' Group
Re: DNS hardening, was Re: Dan Kaminsky
daemon@ATHENA.MIT.EDU (Roland Dobbins)
Wed Aug 5 14:31:00 2009
From: Roland Dobbins <rdobbins@arbor.net>
To: NANOG list <nanog@nanog.org>
In-Reply-To: <4A79CB90.708@mail-abuse.org>
Date: Thu, 6 Aug 2009 01:31:55 +0700
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Aug 6, 2009, at 1:12 AM, Douglas Otis wrote:
> Having major providers support the SCTP option will mitigate
> disruptions caused by DNS DDoS attacks using less resources.
Can you elaborate on this (or are you referring to removing the
spoofing vector?)?
-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>
Unfortunately, inefficiency scales really well.
-- Kevin Lawton