Scaled Back Cybersecuruty

Avi Freedman freedman at freedman.net
Tue Jan 14 20:51:43 UTC 2003


In article <103014.152131.21746 at avi.netaxs.com> Pete wrote:

: I'm trying to envision an RFP that awards business to one or
: a few network operators, but requires that they interoperate
: effectively with other operators who don't win any of the
: business. I've only got a state-level purchasing
: perspective, but I don't see it happening at any level.

Let me be more clear :)

If the next FTS or if all large Federal IP purchases mandated
one of:

- Routers must be configured by end of 2003 so that all packets 
  to the control plane must be logically separated from user
  packets (or demonstrate the ability to take 200mb of attack
  traffic to the router CPU without having an effect) 

OR

- All single-homed customers must be source-address filtered at
  ingress or egress.  (Becoming multi-homed at ingress as a
  requirement over time)

OR 

...

You get the idea.  Something that IS possible, that matters MOST
at the large end of the scale.  And if we go a long way towards
solving one beasty per year we'll at least be making MORE progress
than we've been making to date, which is roughly zero.

: Pete.

Thanks,

Avi




More information about the NANOG mailing list