How to get better security people

Avleen Vig lists-nanog at silverwraith.com
Thu Apr 4 10:19:57 UTC 2002


On Wed, 3 Apr 2002, Richard A Steenbergen wrote:

> As for your service listing them... Smurfs aren't spam, so I'm not sure
> what you plan to accomplish by making the data available via DNS, it would
> really only be useful as a BGP feed. Even then, it's usefulness is
> limited. I suppose you could null route traffic to specific broadcast
> addresses to prevent people originating smurfs from your network with
> minimal impact on legit services, or if you are a big transit provider
> with balls you could apply it to all your customers.

SAFE is a daughter-project of the IRCNetOps project (www.ircnetops.org)
who areIRC network admins from small and large networks who came together
last year after getting rather pissed off by constant DoS attacks.
No, not just little admins with shells on little networks, but also bigger
admins on the bigger networks who run servers at ISP's too.

The service could be used to deny IRC access to their networks to people
who come from broken networks.

> There is no protocol (disclaimer: that I'm aware of) for distributing IP
> lists that could be filtered by source address, let alone other more
> intelligent things like distributing firewall rulesets so you could pick
> off only the echo replies, BUT MAYBE THERE SHOULD BE. <-- HINT!

Maybe there should be :-)
Wnat to do it? ;-)




More information about the NANOG mailing list