North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Is it time to abandon bogon prefix filters?

  • From: Niels Bakker
  • Date: Thu Aug 07 19:03:29 2008

* [email protected] (Randy Bush) [Fri 08 Aug 2008, 00:59 CEST]:
rob,
If the source of a scan or probe is a bogon, we tag it that way in our data store. I went back to 2008-01 and found the following percentages of bogons in our data:
[..]
2008-08: 0.001258054% (thus far)

this is an extremely far cry from 60%. what am i not understanding?


and can you separate reserved (127, ...) and unallocated?

This is scanning of darknets - usually you're interested in what comes back, i.e. can you 0wn it? so src has to be valid.


(D)DoS of course are much more likely to come closer to the 60% number. No need to get the SYN+ACKs or the ICMP echo replies back...


-- Niels.