nanog mailing list archives

Re: RTBH Support Across the Industry


From: Charles Monson via NANOG <nanog () lists nanog org>
Date: Mon, 27 Jul 2026 15:17:31 -0500

Simultaneously we need to push harder to adopt uRPF to prevent spoofed attacks.

I agree with you that better Flowspec adoption would be nice, and better anti-spoofing. But on the anti-spoofing 
point, I think the need for attackers to spoof IPs will go down in the coming years so I think this prevention 
mechanism drop in priority (this is an unfounded gut feeling, nothing backed by data)

To back up this point, the majority of our subscriber base is FTTH
with symmetric download/upload speeds between 100M-1G. In recent
months we've observed a number of subscribers participating in DDoS
attacks sending directly from their address to the victim IP.

Further investigation revealed they had questionable "free" streaming
boxes that had joined them to a residential proxy botnet, which
seemingly decided to switch to DDoS activities after some time.

Anti-spoofing is good, and mitigations should still be put in place,
but it doesn't help much when a few tens/hundreds of compromised hosts
can individually saturate their gigabit upload.


Charles
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/OYA3VCP3PGVUJPURTLZVZLY3X46A5ERF/


Current thread: