Real-Time Mitigation of Denial of Service Attacks Now Available With AT&T

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Wed Jun 2 19:26:28 UTC 2004


On Wed, 02 Jun 2004 11:39:39 MDT, Danny McPherson <danny at tcb.net>  said:

> How do you discriminate *DDOS attacks employing source address spoofing*
> from broken NATs, rampant worms, PMTU and other related misconfiguration
> resulting in backscatter and similar garbage - with filter counters?  

A bogon packet is a bogon packet Filter them all and let the appropriate deity
sort them out (unless you bill by traffic volume ;)

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20040602/56a506bf/attachment.sig>


More information about the NANOG mailing list