how about a well-known DOWNGRADE BGP Community? (Was: RTBH Support Across the Industry)
Job Snijders via NANOG <[email protected]>
| Newsgroups | gmane.org.operators.nanog |
|---|---|
| Message-ID | <[email protected]> |
Dear all, Following up on the RTBH thread, we'd like to put forward an different strategy for DoS attack mitigation. Perhaps just as an extra tool in the toolbox. Abstract -- This document outlines a method to mitigate Denial of Service (DoS) attacks by using a well-known BGP community named "DOWNGRADE" as signal to neighboring networks to treat traffic destined towards "DOWNGRADE" tagged IP prefixes with low precedence. The "downgrade" strategy offers an appealing alternative to Remote Triggered Blackhole (RTBH) filtering, because RTBH filtering completes the DoS attack and hampers the defender's ability to monitor whether the attack is still ongoing. Read the full draft document here: https://datatracker.ietf.org/doc/html/draft-spaghetti-grow-downgrade-bgp-community Your feedback is most welcome! Kind regards, Job _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/[email protected]/message/UGA3PTY45ILBQRASIJJVHAF3M57MQQ5I/