North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

RE: attacking DDOS using BGP communities?

  • From: alex
  • Date: Fri Oct 18 10:30:48 2002

> 
> 701 has a blackhole community, 701:9999, basically it sets the next-hop
> to something blackholed on their edge so the DOS attack gets dropped as
> soon as it hits them. I have made use of this to kill at least one DDOS
> event. A global blackhole community may be difficult to achieve, but
> getting the majority of large providers to implement one is a good
> start.

Brilliant solution - lets stop DDOS attack on the customer by denying
service to the customer is a non-distributed way.

Alex