Re: BGP IP prefix hijack detection times

2017-02-28 Thread Christopher Morrow
On Tue, Feb 28, 2017 at 1:17 AM, Nagarjun Govindraj < nagarjun.govind...@imaginea.com> wrote: > > > I am just trying to distinguish between a legitimate advertisement against > hijack event. > > that's what everyone's trying to do... if you aren't trying to fix things, why do you care about them a

Re: BGP IP prefix hijack detection times

2017-02-27 Thread Nagarjun Govindraj via NANOG
The Goal is not to mitigate or take action against the malicious activity. Goal is to detect the hijacking event by trying to reduce false posivites as much as possible. I know false positives is one of the key factor to consider. I am just trying to distinguish between a legitimate advertisement a

Re: BGP IP prefix hijack detection times

2017-02-27 Thread Hank Nussbacher
On 28/02/2017 07:15, Nagarjun Govindraj via NANOG wrote: So what if you detect in 1.4 minutes of 3.1 minutes? Or even 8 minutes? What then? You certainly couldn't do anything to prevent it after 3.1 minutes. First you need to analyze whether the BGP hijack is a false positive or not. Could be t

Re: BGP IP prefix hijack detection times

2017-02-27 Thread Christopher Morrow
On Tue, Feb 28, 2017 at 12:15 AM, Nagarjun Govindraj < nagarjun.govind...@imaginea.com> wrote: > > Well, the idea behind the mail was to know if anyone in the community are > doing real time BGP IP prefix hijacking. > Like Artemis detection tool claims to be detecting in 1.4 ~ 3.1 minutes. > So I

Re: BGP IP prefix hijack detection times

2017-02-27 Thread Nagarjun Govindraj via NANOG
Well, the idea behind the mail was to know if anyone in the community are doing real time BGP IP prefix hijacking. Like Artemis detection tool claims to be detecting in 1.4 ~ 3.1 minutes. So I wanted to know if anyone in the community are using such tools for detecting hijacks, if yes how much time

Re: BGP IP prefix hijack detection times

2017-02-27 Thread Nick Hilliard
Christopher Morrow wrote: > Also: "How reliable are the alerts being sent?" also: do the smtp servers which handle mail for the domain of the alerting email address use the IP address space as they're notifying about? Nick

Re: BGP IP prefix hijack detection times

2017-02-27 Thread Christopher Morrow
Also: "How reliable are the alerts being sent?" On Mon, Feb 27, 2017 at 12:19 PM, Christopher Morrow < morrowc.li...@gmail.com> wrote: > you probably want to ask the people that make these systems, yes? > > On Sun, Feb 26, 2017 at 7:12 AM, Nagarjun Govindraj via NANOG < > nanog@nanog.org> wrote:

Re: BGP IP prefix hijack detection times

2017-02-27 Thread Christopher Morrow
you probably want to ask the people that make these systems, yes? On Sun, Feb 26, 2017 at 7:12 AM, Nagarjun Govindraj via NANOG < nanog@nanog.org> wrote: > Hi Nanog, > > what are the detection times for BGP IP prefix hijack detection systems > adopted by community members/operators (if any) ? > >

BGP IP prefix hijack detection times

2017-02-26 Thread Nagarjun Govindraj via NANOG
Hi Nanog, what are the detection times for BGP IP prefix hijack detection systems adopted by community members/operators (if any) ? Regards, Nagarjun