ACLs / Filter Lists - Best Practices

Rob Thomas robt at
Fri Nov 30 16:50:28 UTC 2001

Hi again, all.

Ah, this is a topic near and dear to my heart.  :)

] And before someone jumps up and says "theoretical!", I'm sure a few
] NANOGers who double as occasional IRC server admins can possibly
] attest to strangely named channels with hundreds of idling
] clients sitting in them.. :-)

I track between one and ten botnets per day, on IRC networks both public
and private.  They vary in size from five bots to greater than 10K bots.
The average is on the low end, probably less than 100 bots.  The large
botnets (> 2000 bots) are rare, but they do exist.  Ponder the power of
10K bots hitting your border routers with any sort of flood.  <BOOM>

This stuff is quite real, and quite powerful.

Rob Thomas
ASSERT(coffee != empty);

