IP Spoof, Stoppable?
Andrei Robachevsky - writing at CircleID, explores the potential to halt IP Spoofing. Today's MustRead (along with the ISOC whitepaper referred to in the original post).
Mitigating the reflection component of the attack is one way of addressing the problem. As reported by the OpenResolver project, in the last two years the amount of open DNS resolvers has dropped almost by half — from 29M to 15M. However, there are other types of amplifying reflectors — NTP and SSDP are among them, and even TCP-based servers (like web servers, or ftp servers) can reflect and amplify traffic. Andrei Robachevsky - writing at CircleID