netsec-sig - Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more...
Subject: Internet2 Network Security SIG
List archive
Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more...
Chronological Thread
- From: George Loftus <>
- To: "Dale W. Carder" <>
- Cc: "Taylor, Scott J." <>, "Spurling, Shannon" <>, "D'Angelo, Cas (Samuel)" <>, Steven Wallace <>, "" <>, Rob Vietzke <>, John Moore <>, Caroline Weilhamer <>
- Subject: Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more...
- Date: Thu, 22 Oct 2015 15:35:43 +0000
- Accept-language: en-US
- Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
It is great to see such active involvement from so many on this thread. We
appreciate all the input and appreciate Steve Wallace’s efforts in kicking
this off. We wanted you to know that we are following this thread carefully
and see it as a way to gather some input from all of you on how we, as a
community, might work to address this need. We heard from several members
at the Technology Exchange, especially during the Network Member and
Connectors BoF that this is an important issue. We have started some
preliminary talks with some vendors on potential solutions. But there is
nothing better than hearing from all of you, as we have in this thread ,
about what you would like to consider as potential solutions.
- George
> On Oct 22, 2015, at 11:24 AM, Dale W. Carder
> <>
> wrote:
>
> Thus spake Taylor, Scott J.
> ()
> on Wed, Oct 21, 2015 at 02:36:46AM +0000:
>>
>> I’m starting to believe that the IU guys that are doing SCI-Flow (?) have
>> the right model for DDoS mitigation as well as expressing elephant flows.
>> Why can’t when we detect these attacks, we program a controller to drop.
>> I’m also very curious to spend some more time with vendors on the
>> BGP-Flowspec capabilities and maybe using something like that to drop
>> traffic at our edge. Based on what we’ve seen in CT I have to believe we
>> could easily knock out the less sophisticated attacks.
>
> One of our campuses is using fastnetmon monitoring a UDP-only feed
> from a mirror port on our router. With detection in a few seconds,
> it then uses exabgp to inject a flowspec rule into our network to
> block the traffic across our AS. As far as free goes, this is pretty
> much just off the shelf.
>
> Dale
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., (continued)
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Spurling, Shannon, 10/20/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Schopis, Paul, 10/20/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Taylor, Scott J., 10/21/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Schopis, Paul, 10/21/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Mark Montalto, 10/21/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Schopis, Paul, 10/21/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Taylor, Scott J., 10/21/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Schopis, Paul, 10/21/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Spurling, Shannon, 10/21/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Schopis, Paul, 10/21/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Mark Montalto, 10/21/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Dale W. Carder, 10/22/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., George Loftus, 10/22/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Schopis, Paul, 10/22/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Dale W. Carder, 10/22/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Nick Buraglio, 10/22/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Dale W. Carder, 10/22/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Schopis, Paul, 10/21/2015
- Re: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Michael H Lambert, 10/22/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Spurling, Shannon, 10/22/2015
- RE: [Security-WG] fast track for DDoS recommendations to Internet2, and a bit more..., Spurling, Shannon, 10/20/2015
Archive powered by MHonArc 2.6.16.