logo

BCP 38: Mitigating Spoofed DDoS Attacks

ID: 7eff8ca2-1ed3-5200-a2ac-ae26cb0df5b9

STIX ID: report--7eff8ca2-1ed3-5200-a2ac-ae26cb0df5b9

Feed Name: Malware Patrol Blog

Date Published: 2016-07-12

Date Updated: 2026-06-15

Author: Malware Patrol

...
...

This document explains how source-address spoofing is used in DDoS attacks and advocates implementing ingress filtering (BCP 38 / RFC 3704) and reverse-path forwarding (RPF) variants to prevent networks from being abused in amplification, reflection, and SYN-flood attacks; it covers deployment considerations, caveats (asymmetric routing, multihoming), logging recommendations, IPv6 notes, references, and advertises a commercial DDoS threat feed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.