It's just that there is no incentive to stop lazy ISPs from allowing everything since that's easier.
If all ISPs did this, there would be no ACL issue and BCP 38 would solve the problem. No need to make it harder than it is.
I suspect it might reduce out-of-network traffic a bit too..
Or ISPs could check source IPs at edge routers maybe?
Only on HN. Haha.
To impose fixes upstream, you'd have to do DPI on all data; which is not allowed under some laws (i.e. net neutrality).
RFC2827, which should fix the problem where SSDP can be used for DDoS, was published in 2000: https://tools.ietf.org/html/rfc2827
Is ingress filtering on layer 3 considered DPI?
I would not consider the comparison of the source address of packets crossing an ingress link to be 'deep'. I consider that check to be very shallow. It needn't even be every packet from a set, merely picking a random (actually random) packet and testing for conformity is a good quality control measure that SHOULD be taken.
What would the comparison be against? Routers are supposed to know which links are on the other side of all down-stream connections so that they can effectively route.