Re: "general badness" AS-based reputation system

2011-09-28 Thread Serranos
On Sep 26, 2011, at 02:23 , Manish Karir wrote: > We tried to outline some of the challenges of building such a system in our > NANOG52 presentation: > > http://www.merit.edu/networkresearch/papers/pdf/2011/NANOG52_reputation-nanog.pdf > > In particular see slide 4. where we tried to lay down w

Re: "general badness" AS-based reputation system

2011-09-26 Thread Gadi Evron
We tried to outline some of the challenges of building such a system in our NANOG52 presentation: http://www.merit.edu/networkresearch/papers/pdf/2011/NANOG52_reputation-nanog.pdf In particular see slide 4. where we tried to lay down what we think the requirements are for a socially acceptable

Re: "general badness" AS-based reputation system

2011-09-26 Thread Gadi Evron
On 9/26/11 2:31 AM, Jimmy Hess wrote: Sorry... what makes you think the problem with use of a AS-reputation systems is social and not technical? IP packets are not stamped with the numbers of any of the AS they transitted to reach your network. The IP protocol simply does not expose AS number i

Re: "general badness" AS-based reputation system

2011-09-26 Thread Tom Vest
On Sep 26, 2011, at 1:11 AM, Manish Karir wrote: > > On Sep 25, 2011, at 11:31 PM, Tom Vest wrote: > >> >> On Sep 25, 2011, at 9:23 PM, Manish Karir wrote: >> >>> On Sep 25, 2011, at 6:31 PM, nanog-requ...@nanog.org wrote: >>> Message: 9 Date: Sun, 25 Sep 2011 18:37:17 +0300 F

Re: "general badness" AS-based reputation system

2011-09-25 Thread Suresh Ramasubramanian
I would probably limit this to simply identifying rogue prefixes [such as those prefixes - and there are some - owned entirely by criminal spammers, botnet C&Cs etc] [let us not get into a discussion on listing criteria or what constitutes criminal spam just now, there's a whole lot of such discus

Re: "general badness" AS-based reputation system

2011-09-25 Thread Manish Karir
On Sep 25, 2011, at 11:31 PM, Tom Vest wrote: > > On Sep 25, 2011, at 9:23 PM, Manish Karir wrote: > >> On Sep 25, 2011, at 6:31 PM, nanog-requ...@nanog.org wrote: >> >>> Message: 9 >>> Date: Sun, 25 Sep 2011 18:37:17 +0300 >>> From: Gadi Evron >>> To: nanog@nanog.org >>> Subject: "general ba

Re: "general badness" AS-based reputation system

2011-09-25 Thread Tom Vest
On Sep 25, 2011, at 9:23 PM, Manish Karir wrote: > On Sep 25, 2011, at 6:31 PM, nanog-requ...@nanog.org wrote: > >> Message: 9 >> Date: Sun, 25 Sep 2011 18:37:17 +0300 >> From: Gadi Evron >> To: nanog@nanog.org >> Subject: "general badness" AS-based reputation system >> Message-ID: <4e7f4aad.80

Re: "general badness" AS-based reputation system

2011-09-25 Thread Manish Karir
On Sep 25, 2011, at 6:31 PM, nanog-requ...@nanog.org wrote: > Message: 9 > Date: Sun, 25 Sep 2011 18:37:17 +0300 > From: Gadi Evron > To: nanog@nanog.org > Subject: "general badness" AS-based reputation system > Message-ID: <4e7f4aad.8020...@linuxbox.org> > Content-Type: text/plain; charset=ISO

Re: "general badness" AS-based reputation system

2011-09-25 Thread Jimmy Hess
On Sun, Sep 25, 2011 at 10:37 AM, Gadi Evron wrote: > In my opinion, third-party security based AS-reputation systems will > eventually become de-facto border filtering systems for ISPs, but that day > is still not here, as that is still socially unacceptable in our circles, > and will remain so u