Blackhole for network security

There is a few paper on the net discuss how to divert and mitigate the damages caused by network attacks, in particular DDOS. Both papers describe a means to create a “black hole” on the network.

One is on the network layer and one is on the web server layer
Cisco Black Hole Filtering
Cisco's paper explain a specifically built infrastructure can help ISP to route malicious packets to a null interface(blackhole filtering).

Microsoft Beat Hackers At Their Own Game With A Hackerbasher Site
Utilizing the principle that all vistors must know my name. This method divert incoming traffic using IP address not hostname.

These papers give a good illustration that security can be achieved by thoughtful design. All the tools and technology is available to everyone or what they call built-in. By good designing, we increase the effectiveness of our security investment.

Comments

Popular posts from this blog

Risk on Radio

One source of poverty

Root Certificate update and software design