Why would that not solve a large part of the problem?
Thank you in advance.
Why would that not solve a large part of the problem?
Thank you in advance.
As a customer, I don't want my ISP screwing with my traffic. As a provider, I don't want any customers complaining because we screw with their traffic.
To block monlist and only monlist queries, we'd have to be looking into the layer 7 payload of IP traffic. I'd rather not do that.
The brute-force method would be to block traffic to/from 123/UDP but that's gonna mess up a lot of stuff (including my own).
Cisco, Juniper etc. who manufacture high end routers would certainly love it.
A better alternative is to stop or limit source ip spoofing, because you can filter it on the interfaces connecting smaller providers and customers rather than the most resource-constrained routes to other backbone providers. And that's slowly happening (I'm saying, while looking at tcpdump output from a SYN attack that might very well use spoofed IPs). It's simpler because you "only" need a single lookup against a few bytes per packet per interface instead of potentially having a long list of patterns to check against the whole packet.
> and who I would expect to incorporate best practices
Don't bet on it. They will when it makes a big difference to them. But for many of these types of attack you'll see purely reactive reactions because it's often far cheaper (for them) vs. the costs of routing hardware etc. that can do enough processing per packet to be viable.
However, Tier 1 providers should not in any way police the internet.