<?xml version='1.0' encoding='UTF-8'?>

<reference anchor='I-D.zinin-rtg-dos'>
<front>
<title>Protecting Internet Routing Infrastructure from Outsider DoS Attacks</title>

<author initials='A' surname='Zinin' fullname='Alex  Zinin'>
    <organization />
</author>

<date month='May' day='23' year='2005' />

<abstract><t>The mechanism described in this document helps to secure an Internet Service Provider's router infrastructure from outsider attacks, including (but not limited to) Distributed denial of service (DDoS) attacks based on CPU and/or queue exhaustion (e.g., TCP SYN flooding and flooding of invalid MD5-signed routing protocol packets.) The presented approach is based on explicitly marking control packets from trusted sources by different link-layer encapsulation and does not require any modifications to user data exchange protocols, ICMP, routing protocols or changes to existing hardware in routers, which allows it to be deployed quickly throughout the Internet.</t></abstract>

</front>

<seriesInfo name='Internet-Draft' value='draft-zinin-rtg-dos-02' />
<format type='TXT'
        target='http://www.ietf.org/internet-drafts/draft-zinin-rtg-dos-02.txt' />
</reference>

