North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Peering with the Internet Alert Registry

  • From: Christopher Morrow
  • Date: Mon Mar 10 18:07:58 2008
  • Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=kdUynRH/Z9PSOinhfP8ZLHINVTVqUYldyH1SFb0kEsI=; b=bxiuyqVmjNYGlBeoRAqZrXUDxKUWwT+F8clEBiBFnootM4Ez5lwSBcvg/4cVjnDwuQc2jcT46GyEsRsCX43tMXi/3pM7Yp8qGbF43yTVywpRY4XlaV+Z1vu5ijfuNgd09TJwAE8Q/eu1k3e4DgRgsFNCeaIfWC2wsYyYXyTKrF0=
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=TnJZsyuFGbGiF+/w2KtaHmF8ui8HkROgBRGHQAP3HT3JLDU8PxXvkx3SiL+LkUmw+ke/2yMlwgQJ5Uq9MCV4cpdxfRqmtqoxD1Wn5ORl4afpbNsSSRMBxY5xqi9hUvZaNZTwHVA7naAijIdtAoHXUBmM3Gjh8J2fVEB6922cSEA=

On Mon, Mar 10, 2008 at 11:01 AM, Josh Karlin <[email protected]> wrote:
> All,
>
> Some of you are aware of the site for network operators:
> http://iar.cs.unm.edu/  which has running for two years now.  The purpose of
> the site is to detect and distribute network anomaly information to the
> network operators that need to know.  The flip side of our proposed security
> system, Pretty Good BGP (PGBGP), lowers the local preference of anomalous
> routes on BGP routers for 24 hours, giving operators time to respond to
> anomalous routes before they can fully propagate.
>

does pgbgp toss out alerts/snmp-traps/log-messages when these
anomalous announcements arrive? if not, how does one know they are
inside the 24hr window?