gmmoura / draft-moura-dnsop-authoritative-recommendations

draft-moura-dnsop-authoritative-recommendations
1 stars 0 forks source link

Address BGP blackholing #9

Open gmmoura opened 5 years ago

gmmoura commented 5 years ago

[KDar03]

[Moura16b] speculates that more careful, explicit, and automated management of policies may provide stronger defenses to overload, an area currently under study. For DNS operators, that means that besides traditional filtering, two other options are available (withdraw/prepend/communities or isolate instances), and the best choice depends on the specifics of the attack. Null routing (BGP blackholing) can also be applied to NOT move the attack to other sites but avoid collateral damage.

mdavids commented 5 years ago

I support some text along these lines. BGP blackholing is a well known, well understood, commonly used technique. There is ample proof of and consensus over its usefulness. In my mind it is a useful addition to R4:, second bullet (absorber), as an example like we did for #3. It can make an absorber less degraded under certain circumstances (for example when the source of an attack is only one or a few AS-es).

gmmoura commented 5 years ago

@hardaker , wanna take a shot at this? thansk