Re: Is Denial of Service a WEIRD Hot Topic?

Ray Plzak <[email protected]> Wed, 16 Feb 2000 06:58:56 -0500 (EST)
Newsgroups gmane.ietf.weird
Message-ID <[email protected]>
While this is certainly the topic d'jour, there are two ways to look at
how it can be addressed.  First, are putting up a tutorial type of
service?  If so then maybe what we do is point to the resources that are
already there such as the site that Paul Ferguson and Dan Senie have at
URL http://www.denialinfo.com/.  We don't want to reinvent the wheel.
Second, we can highlight IETF activity in this area, of which the message
below is a example of one part of the solution to the problem.  This has
some value in its timeliness, but does not point out all of the
discussions about this problem.  There are other RFCs and IDs that address
aspects of this as well.  They should be highlighted as well.  A keyword
search capability that would find these documents would certainly be
helpful here.  The effort here is obviously an upfront one to decide how
to set up the mechanism - perhaps a web crawler type tool that looks at
certain types of info at selected sites - RFCs, IDs, IETF mail list
archives, etc.  Food for thought.

Ray


On Tue, 15 Feb 2000, Burke Chris-CCB007 wrote:

> Any thoughts on whether this type of information is worth highlighting on
> the web site? Chris
> 
> > -----Original Message-----
> > From:	The IESG [SMTP:[email protected]]
> > Sent:	Tuesday, February 15, 2000 6:24 AM
> > Cc:	RFC Editor; Internet Architecture Board
> > Subject:	Protocol Action: Network Ingress Filtering: Defeating Denial
> > of Service Attacks which employ IP Source Address Spoofing to BCP
> > 
> > 
> > 
> > The IESG has approved 'Network Ingress Filtering: Defeating Denial of
> > Service Attacks which employ IP Source Address Spoofing' <rfc2267> as a
> > Best Current Practice.
> > 
> > The IESG Contact Persons are Randy Bush and Bert Wijnen.
> > 
> >  
> > Technical Summary
> >  
> >  This document describes recommended router configurations to reduce
> >  likelihood of attacks over the network.  It describes how an ISP customer
> >  aggregation router should be configured to prevent a customer from
> > sending
> >  packets with source addresses from space other than their own.
> > 
> > Working Group Summary
> > 
> >  This is not the product of a working group, but has been used in
> > practice,
> >  has passed general IETF last call twice, and is generally considered to
> > be
> >  good practice.
> > 
> > Protocol Quality
> > 
> >  This was reviewed for the IESG by Randy Bush.
>