Title: Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing
Author(s): P. Ferguson, D. Senie.
Status: BEST CURRENT PRACTICE
Date: May 2000
Length: 21258
Obsoletes: RFC2267
Updated by: RFC3704
Recent occurrences of various Denial of Service (DoS) attacks which have employed forged source addresses have proven to be a troublesome issue for Internet Service Providers and the Internet community overall. This paper discusses a simple, effective, and straightforward method for using ingress traffic filtering to prohibit DoS attacks which use forged IP addresses to be propagated from 'behind' an Internet Service Provider's (ISP) aggregation point.
|
|
|