nanog mailing list archives
RE: UDP port 80 DDoS attack
From: George Bonser <gbonser () seven com>
Date: Wed, 8 Feb 2012 18:26:42 +0000
77% of all networks seem to think so. http://spoofer.csail.mit.edu/summary.php
And it would be the remaining 23% that really need to understand how difficult they are making life for the rest of the Internet.
However the remaining networks allow spoofed traffic to egress their networks. When that traffic enters my network, I have no method whatsoever to differentiate it from any other traffic.
I'm not really thinking about traffic coming from the Internet. I'm thinking about its originating location. Correct, once it gets into the Internet, you really have no way to tell.
I could ask my upstream where they see it coming from, which will be quite hard if they do not have pretty fancy systems.
At that point the game is really hard, agreed. And if it is distributed, it could be coming from any number of places or from every single one of their upstreams.
But if they receive it from a peer, I am as good as lost in trying to find the culprit.
Agreed. That's why it is important to stop it at the source.
Bas
Current thread:
- Re: UDP port 80 DDoS attack, (continued)
- Re: UDP port 80 DDoS attack Keegan Holley (Feb 05)
- Re: UDP port 80 DDoS attack Dobbins, Roland (Feb 05)
- Re: UDP port 80 DDoS attack bas (Feb 07)
- RE: UDP port 80 DDoS attack George Bonser (Feb 08)
- Re: UDP port 80 DDoS attack Keegan Holley (Feb 08)
- RE: UDP port 80 DDoS attack George Bonser (Feb 08)
- Re: UDP port 80 DDoS attack Keegan Holley (Feb 08)
- RE: UDP port 80 DDoS attack George Bonser (Feb 08)
- RE: UDP port 80 DDoS attack George Bonser (Feb 08)
- Re: UDP port 80 DDoS attack bas (Feb 08)
- RE: UDP port 80 DDoS attack George Bonser (Feb 08)
- Re: UDP port 80 DDoS attack Keegan Holley (Feb 08)
- RE: UDP port 80 DDoS attack Drew Weaver (Feb 08)
- RE: UDP port 80 DDoS attack Sven Olaf Kamphuis (Feb 09)
- Re: UDP port 80 DDoS attack Steve Bertrand (Feb 09)
- Re: UDP port 80 DDoS attack Keegan Holley (Feb 09)
- Re: UDP port 80 DDoS attack Keegan Holley (Feb 08)
- Re: UDP port 80 DDoS attack Christopher Morrow (Feb 08)
- RE: UDP port 80 DDoS attack George Bonser (Feb 08)
- Re: UDP port 80 DDoS attack Mark Andrews (Feb 08)
- Re: UDP port 80 DDoS attack Keegan Holley (Feb 08)