Title: Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing
Author(s): P. Ferguson, D. Senie.
Status: INFORMATIONAL
Date: Jan 1998
Length: 21032
Obsoleted by: RFC2827
Recent occurrences of various Denial of Service (DoS) attacks which have employed forged source addresses have proven to be a troublesome issue for Internet Service Providers and the Internet community overall. This paper discusses a simple, effective, and straightforward method for using ingress traffic filtering to prohibit DoS attacks which use forged IP addresses to be propagated from 'behind' an Internet Service Provider's (ISP) aggregation point.
|
|
|