[70624] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: handling ddos attacks

daemon@ATHENA.MIT.EDU (Vincent Gillet - Opentransit)
Thu May 20 17:01:48 2004

Date: Thu, 20 May 2004 22:53:54 +0200
From: Vincent Gillet - Opentransit <vgi@zoreil.com>
To: Jared Mauch <jared@puck.nether.net>
Cc: Mark Kent <mark@noc.mainstreet.net>, nanog@merit.edu
In-Reply-To: <20040520190112.GA18495@puck.nether.net>
Errors-To: owner-nanog-outgoing@merit.edu


jared@puck.nether.net disait :

> 
> On Thu, May 20, 2004 at 11:52:01AM -0700, Mark Kent wrote:
> > 
> > I've been trying to find out what the current BCP is for handling ddos
> > attacks.  Mostly what I find is material about how to be a good
> > net.citizen (we already are), how to tune a kernel to better withstand
> > a syn flood, router stuff you can do to protect hosts behind it, how
> > to track the attack back to the source, how to determine the nature of
> > the traffic, etc.
> > 
> > But I don't care about most of that.  I care that a gazillion
> > pps are crushing our border routers (7206/npe-g1).
> > 
> > Other than getting bigger routers, is it still the case that the best
> > we can do is identify the target IP (with netflow, for example) and
> > have upstreams blackhole it?
> 
> 	or acl it.
> 
> 	some providers offer blackhole services where you can inject
> a route to them via bgp over the same session (with communities) or
> over a different session that just takes blackhole routes..
> 
> 	that can be used by you to cause them to null0/discard the
> traffic within their network automatically..

At last Ripe meeting, i made a presentation about the way France Telecom
is handling DDOS attack :

	http://www.ripe.net/ripe/meetings/ripe-48/eof.html#nocexp

Slides at

	http://www.ripe.net/ripe/meetings/ripe-48/presentations/ripe48-eof-gillet.pdf

We presented our practice from a NOC perspective (ACL, blackhole, sinkhole,
netflow, sample, ... etc) and our next steps.

We proposed to give this presentation at coming Nanog, but we were not
so succesfull. Next nanog meeting maybe ...

Vincent.

home help back first fref pref prev next nref lref last post