Re: Speaking of spamhaus...

Dave Warren <[email protected]> Thu, 28 Mar 2013 14:26:19 -0700
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 2013-03-28 07:57, Dan Oetting wrote:
> On Mar 27, 2013, at 9:26, Barry Shein <[email protected]> wrote:
>
>> Possibly interesting:
>>
>> Big DDoS against SpamHaus, allegedly by CyberBunker...
>>
>>   http://www.bbc.co.uk/news/technology-21954636
> Why are forged source addresses tolerated?
>
> I don't care how convoluted the network is, eventually it gets down to a few gateways into a zone with a well defined set of valid addresses. At those gateways they can implement egress filtering to keep invalid packets from getting out. In the wider network where bandwidths may be too high or routing maps too complex for real time filtering, sampling can be employed to detect probably sources of forged addresses.

In more complicated network environments where your customer owns their 
own IPs, they might well use split routing techniques which generates 
traffic that isn't forged in a practical sense, but from a technical 
perspective, it's indistinguishable.

This is a solvable problem, but inertia is powerful, change is painful.

I still remember a time when I had a couple consumer/SMB grade 
connections and could route outbound packets indiscriminately between 
the two, taking advantage of my DSL provider's static subnet and my 
cable modem's faster upstream. Good times, while it lasted.

-- 
Dave Warren
http://www.hireahit.com/
http://ca.linkedin.com/in/davejwarren

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org