netsec-sig - RE: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing
Subject: Internet2 Network Security SIG
List archive
- From: Michael Hare <>
- To: Paul Howell <>, David Farmer <>, "" <>, Grover Browning <>
- Cc: "" <>, "" <>, "" <>
- Subject: RE: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing
- Date: Wed, 27 Jul 2016 13:53:09 +0000
- Accept-language: en-US
- Authentication-results: spf=none (sender IP is ) ;
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
Paul [and others], When/if accounting announcements becomes a priority, I'd recommend having a look at exaBGP. I'm using it inside AS 3128 [and a small perl script, less than 100
lines] to log all RIB changes to JSON. I currently roll up daily summaries based on this data. Feel free to contact me off-list for any details. As far as traffic counts being blocked, that's tricky. On the MX line we have an output filter on the dsc0 interface which will give you per router info [and
firewall filter detail level of what is dropped] but this won't give you stats per route/event. I think we could port mirror out a real interface but we haven't wanted to burn port or forwarding capacity to do this. -Michael From: [mailto:]
On Behalf Of Paul Howell Hi, To answer the question about monitoring current BH announcements, we don’t have automated monitoring & reporting in place for this but I have been routinely checking the BH
announcements via the router proxy and have not found a time when there wasn’t at /32 and/or /24 being blocked. Spot checking just now, there about 30 prefixes being blocked with several that are 8 weeks old and some that are about 4 days old.
I agree that statistics and trends would be good to have on this and it’s on the list of items to do but I can’t promise that it’ll be completed by Jan 2017. Regards, Paul === Paul Howell Chief Cyberinfrastructure Security Officer Network Services, Internet2 100 Phoenix Drive, STE 111 Ann Arbor, MI 48108 Office: 734-352-4212 Email:
From:
David Farmer <> On Tue, Jul 26, 2016 at 9:46 AM, John Kristoff <> wrote:
That's a really good question, Grover, Paul? I was thinking about this last night too. I'd like to know; how many routes/IPs are blackholed, how often, what duration, some idea of the amount of traffic dropped, maybe how much each router
is dropping. Just doing some brainstorming, please don't actually take that as a formal request, at least yet.
Like I said I'm skeptical of this really being useful, mostly because I too would only really consider this for routes for this community, and while there is a component of some DOS attacks coming from within this community it is a relatively
small part of the overall issue most of the time.
This sounds interesting and maybe a more useful way to think about this, could you flesh this out a bit more. Thanks
-- =============================================== |
- RE: [Security-WG] [NTAC] New Well-Known BGP Community for Blackholing, (continued)
- RE: [Security-WG] [NTAC] New Well-Known BGP Community for Blackholing, Michael Hare, 07/26/2016
- [Security-WG] Re: [NTAC] New Well-Known BGP Community for Blackholing, Grover Browning, 07/26/2016
- [Security-WG] Re: [NTAC] New Well-Known BGP Community for Blackholing, Spears, Christopher M., 07/26/2016
- [Security-WG] RE: [NTAC] New Well-Known BGP Community for Blackholing, Michael Hare, 07/26/2016
- [Security-WG] Re: [NTAC] New Well-Known BGP Community for Blackholing, Bill Jensen, 07/26/2016
- [Security-WG] Re: [NTAC] New Well-Known BGP Community for Blackholing, David Farmer, 07/26/2016
- [Security-WG] Re: [NTAC] New Well-Known BGP Community for Blackholing, David Farmer, 07/26/2016
- [Security-WG] Re: [NTAC] New Well-Known BGP Community for Blackholing, Spears, Christopher M., 07/26/2016
- Re: [Security-WG] New Well-Known BGP Community for Blackholing, John Kristoff, 07/26/2016
- Re: [Security-WG] New Well-Known BGP Community for Blackholing, David Farmer, 07/26/2016
- Re: [Security-WG] New Well-Known BGP Community for Blackholing, Paul Howell, 07/27/2016
- RE: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing, Michael Hare, 07/27/2016
- Re: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing, Matthew J Zekauskas, 07/27/2016
- RE: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing, Michael Hare, 07/27/2016
- RE: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing, Spurling, Shannon, 07/27/2016
- RE: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing, Michael Hare, 07/27/2016
- Re: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing, Matthew J Zekauskas, 07/27/2016
- RE: [Qt-security] [Security-WG] New Well-Known BGP Community for Blackholing, Michael Hare, 07/27/2016
- Re: [Security-WG] New Well-Known BGP Community for Blackholing, John Kristoff, 07/27/2016
- Re: [Security-WG] New Well-Known BGP Community for Blackholing, Paul Howell, 07/27/2016
- Re: [Security-WG] New Well-Known BGP Community for Blackholing, David Farmer, 07/26/2016
Archive powered by MHonArc 2.6.19.