Russ

Author Archives: Russ

Openfabric: A Short Video of the IETF Presentation

The most current version of the draft can be found here. There is one more comment from Uma that still needs to be addressed, and one more section that needs to be added. There will probably be more changes, as well, over time. These sorts of drafts do not happen through one person; a number of folks have worked on various bits of the draft, including Shawn, Nikos, Ivan, Les, Naiming, Uma, and others—the folks who have added ideas, etc., are included in the contributors section, which is always worth paying attention to!

The post Openfabric: A Short Video of the IETF Presentation appeared first on 'net work.

Distributed Denial of Service Open Threat Signaling (DOTS)

When the inevitable 2AM call happens—”our network is under attack”—what do you do? After running through the OODA loop (1, 2, 3, 4), used communities to distribute the attack as much as possible, mitigated the attack where possible, and now you realist there little you can do locally. What now? You need to wander out on the ‘net and try to figure out how to stop this thing. You could try to use flowspec, but many providers do not like to support flowspec, because it directly impacts the forwarding performance of their edge boxes. Further, flowspec, used in this situation, doesn’t really work to walk the attack back to its source; the provider’s network is still impact by the DDoS attack.

This is where DOTS comes in. There are four components of DOTS, as shown below (taken directly from the relevant draft)—

The best place to start is with the attack target—that’s you, at 6AM, after trying to chase this thing down for a few hours, panicked because the office is about to open, and your network is still down. Within your network there would also be a DOTS client; this would be a small piece of software running Continue reading

1 91 92 93 94 95 159