[nsp-sec] CUTRS: Community Unwanted Traffic Removal Service

Rabbi Rob Thomas robt at cymru.com
Tue May 20 09:57:03 EDT 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi, David.

> I would be interested in just receiving the raw data and turning it into announcements (then I can choose which should be S/RBTH and which should be flowspec etc..)

We might be able to auto-generate a text file for this purpose.  I say
*might* because I'm not the one coding this project, so I don't want to
wipe that on someone else.  :)  Would a text file work for you?

> The current systems using BGP are great, but I almost never let them get
> propagated in the network directly, instead I capture, parse/vet  and re-advertise if it looks safe to do so.

That's a great approach.

> Would just receiving the data (including. a reason) be an option here?

Oooo you had me until "including a reason."  :)  We won't have that
insight.  We're the messengers, passing along a BGP update.  If we're
going to add some additional input requirements, I think this becomes a
bit more complicated and perhaps less automated.  I'd like to crawl
before we run.

Thoughts?

Thanks!
Rob.
- --
Rabbi Rob Thomas
Team Cymru                                https://www.team-cymru.org/
"Of all tyrannies, a tyranny sincerely exercised for the good of its
 victims may be the most oppressive." - C.S. Lewis

-----BEGIN PGP SIGNATURE-----

iQCVAwUBU3tfL1kX3QAo5sgJAQKTaQP/ZZRJ0zFzwvAb4wJ6LU8KMSAA6vWHmuJo
/pC/on15F+//E0frSzPgqr4+ce5Gn0kD/p/61sR4anERYnoRp/GrvHAMZnGN/CIK
qJwR48vCGk9nEcfcysTaveEw1W52gVM8O7XJ2npyxbvY/mA3Y3/m8J/+WI3104YB
mgF3hNm6S1c=
=rakm
-----END PGP SIGNATURE-----



More information about the nsp-security mailing list