In the last post in this series, we examined the importance of filtering source IP addresses that were considered “bogons”. In this post, we examine more anti-spoofing techniques that can help foil DDoS attacks per RFC 2276 Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing. RFC 2276 provides us with an excellent idea. Why not protect Service Provider clouds, and potentially other “internal” networks, with powerful filters that will check the overall “sanity” of source IP addresses. Combine this with the anti-spoofing techniques shared with you in the first two parts of this series, and you begin to foil many, many different attacks in this category.




