[32131] in North American Network Operators' Group
Re: Defeating DoS Attacks Through Accountability
daemon@ATHENA.MIT.EDU (Mark Prior)
Sun Nov 12 00:22:59 2000
To: "Barry Raveendran Greene" <bgreene@cisco.com>
Cc: "Mark Mentovai" <mark-list@mentovai.com>,
"Simon Lyall" <simon.lyall@ihug.co.nz>, nanog@merit.edu
In-reply-to: Your message of "Sat, 11 Nov 2000 13:46:45 -0800."
<017501c04c28$e31aa170$4f01a8c0@bgreenent2.cisco.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-ID: <12400.974006390.1@connect.com.au>
Date: Sun, 12 Nov 2000 15:49:50 +1030
From: Mark Prior <mrp@connect.com.au>
Message-Id: <20001112051956.556FC10B25@kuji.off.connect.com.au>
Errors-To: owner-nanog-outgoing@merit.edu
> I'll put it this way: filtering should be done against blocks that a
> customer can announce, not against blocks that a customer is actively
> announcing. If you're filtering purely against current advertisements,
> you're bound to break something sooner or later.
Good theory. But what one public source do all the ISP agree to validate the
authority to announce?
I can't ever see this problem being solved while legacy (swamp) space
exists and the organisations using it can just appear anywhere.
Mark.