Re: A DDOS proposal.
From: Matt
Date: Sat, 12 Feb 2000 04:15:26 -0800
Date: Sat, 12 Feb 2000 04:15:26 -0800

The chief concern with DDOS attacks is, as Mr. Rulu points out, that it is not
feasible to protect the entire net.  Morover, he is correct that the solution
he proposes would bring with it severe DOS and even new DDOS opportunities, strong
authentication notwithstanding.  Of course, the issues of international legal
enforcement, liability, etc are glossed over or ignored.  In short, adopting a
massive Panic Button system, as suggested, would probably open more holes than
it would close, and many of the recommended remedies (fire alarm penalties,
for instance) would be difficult or impossible to enforce in many circumstances.

The secret, I think, to limiting vulnerability to these sorts of attacks, and
limiting exposure, is to cause _someone_ (it doesn't particularly matter who)
to internalize the external costs of protection.  That is, since (say) the
University of California at Santa Barbara has less (theoretical) personal stake
in detecting DDOS agents on compromised clients, they will expend no effort to
do so.  If they fully internalized the costs of the damage, however (if CNN
could, for instance, reliably collect the entire potential damages due to loss
of service), they would have a greater incentive.  The solution, then, becomes
primarily technical- a reliable, trustworthy means of identifying the author of
a certain packet would need to be obtained, so that packets could not be spoofed.

It should be remembered, too, that legal sanction against (for instance) ISPs will
be difficult to enforce in practice.  My computer doesn't much care, or notice,
if it is being flooded by Rwandan networks or Australian- service is just as
denied either way.  Legal sanctions against foreign ISPs, however, are very difficult
to enforce.  Sanctions would have to transcend law and political boundaries meaning
network wide isolation of offensive networks, not liability assessments.


