Re: RTBH Support Across the Industry

Charles Monson via NANOG <[email protected]> Mon, 27 Jul 2026 15:17:31 -0500
Newsgroups gmane.org.operators.nanog
Message-ID <CAAbPayLb=Dhj5NmsQBwcw_01e3nnToYkarq3=03Ex+MoX=rYWw@mail.gmail.com>
> > Simultaneously we need to push harder to adopt uRPF to prevent spoofed attacks.
>
> I agree with you that better Flowspec adoption would be nice, and better anti-spoofing. But on the anti-spoofing point, I think the need for attackers to spoof IPs will go down in the coming years so I think this prevention mechanism drop in priority (this is an unfounded gut feeling, nothing backed by data)

To back up this point, the majority of our subscriber base is FTTH
with symmetric download/upload speeds between 100M-1G. In recent
months we've observed a number of subscribers participating in DDoS
attacks sending directly from their address to the victim IP.

Further investigation revealed they had questionable "free" streaming
boxes that had joined them to a residential proxy botnet, which
seemingly decided to switch to DDoS activities after some time.

Anti-spoofing is good, and mitigations should still be put in place,
but it doesn't help much when a few tens/hundreds of compromised hosts
can individually saturate their gigabit upload.


Charles
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/[email protected]/message/OYA3VCP3PGVUJPURTLZVZLY3X46A5ERF/