Skip to main content

Do More to Prevent DNS DDoS Attacks

In recent weeks, numerous high profile organizations and financial institutions have been targets of massive service disruption attacks. 
Several of these attacks are characteristically similar to attacks against top level domain name servers in 2006.
 ICANN’s Security and Stability Advisory Committee published an Advisory, SAC008 [PDF, 963 KB]: Distributed Denial of Service (DDoS) Attacks, shortly after the 2006 incidents. 
Recommendations from that Advisory remain relevant today. 

DDoS attacks commonly use IP addresses that are not allocated to the subscriber or IP addresses from reserved/private space to make it difficult to identify sources of attack traffic. This is called IP address spoofing. Access service providers or corporations should apply network ingress filtering (described in SAC004 and recommended by the Internet IAB in BCP038) to prevent spoofing. Squelching attack traffic close to its origins has the added benefit of relieving ISPs from forwarding malicious or criminal traffic. Everyone benefits when every operator filters spoofed source addresses, except would be attackers.

See more at: http://blog.icann.org/2013/04/do-more-to-prevent-dns-ddos-attacks/#

Comments

Popular posts from this blog

Feedly launches 'Feedly Cloud' sync platform, new web interface

Feedly, one of the leading Google Reader replacement services, announced major restructuring of its services today with a new cloud infrastructure and web interface. Posted on its official blog, Feedly unveiled what it calls "Feedly Cloud", a scalable infrastructure it says is ready to replace Google Reader. The new Feedly Cloud provides several benefits, the first of which is one-click import from Google Reader -- new users to the service can now simply pull everything over seamlessly from their Google account and start using Feedly right away. Existing users will simply have to make sure that they have the latest version of Feedly installed, and their accounts will be migrated to Feedly Cloud over the next few days. Additionally, the new service allowed Feedly to create a stand-alone web interface (found simply at cloud.feedly.com) that works in all major browsers without plugins or extensions. The transition to Feedly Cloud has another benefit, and that is the abilit...

Romanian profanity (înjurătură)

This includes simple verbs and verb phrases. a da la untura lu binica : to have sexual intercourse; very used by the romanian community in Meudon a (şi-)o pune : to have sexual intercourse (literally "to put it," "it" being the penis) Jucăm o Biliboacă : to have oral sex (literally "Let's play Biliboaca" - it suggests that you take the balls in your mouth and shake your head while sucking the balls) a (i-)o da la chechereş : to have sexual intercourse (literally "to give it," "it" being the penis) a suge inima : to have oral sex(literally "to suck the heart,") a şi-o trage : to have sexual intercourse (literally "to pull it," with "it," as above, being the penis) a da în geantă : to have sexual intercourse (literally "to hit the purse") a băga mielu' la căldură : to have sexual intercourse (literally "to take the lamb somewhere warm") a băga lemnul in sobă : to have sex...

Google+ Rolls Out Restricted Communities for Corporate Users

Google this week rolled out a new Google+ security feature for organizations intended to help them keep certain conversations private from the larger Web. Much like Microsoft's Yammer, Google+ restricted communities will only allow access to approved employees. "Whether it's designs of your beta product or notes from your team off-site, anything you post will remain restricted to the organization," Google+ product manager Michael Cai wrote in a blog post. Community administrators can decide whether the site will remain open to everyone at the company, or kept private by invitation only. Google+ also allows for people outside of your domain — clients, agencies, business partners — to join the conversation.