Dear all,

Following up on a recent NANOG thread on RTBH [1], [2]; we'd like to put
forward an different strategy for DoS attack mitigation. Perhaps just as
an extra tool in the toolbox?

   Abstract --
   This document outlines a method to mitigate Denial of Service (DoS)
   attacks by using a well-known BGP community named "DOWNGRADE" as signal
   to neighboring networks to treat traffic destined towards "DOWNGRADE"
   tagged IP prefixes with low precedence. The "downgrade" strategy
   offers an appealing alternative to Remote Triggered Blackhole (RTBH)
   filtering, because RTBH filtering completes the DoS attack and hampers
   the defender's ability to monitor whether the attack is still ongoing.

Please read the full draft document here:

        
https://datatracker.ietf.org/doc/html/draft-spaghetti-grow-downgrade-bgp-community

Your feedback is most welcome!

Kind regards,

Job

[1]: 
https://lists.nanog.org/archives/list/[email protected]/message/LOWUU7RHOKTYKVGWRHNXQJ3GSJYN3HLE/
[2]: 
https://lists.nanog.org/archives/list/[email protected]/message/ITDOCC6N5VELZ56F6ILVZODZSUWH3TNE/

_______________________________________________
GROW mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to