Detailed Information for the Best Practice: 9-6-8093

Number 9-6-8093
Priority Critical
Description Validate Source Addresses: Service Providers should validate the source address of all traffic sent from the customer for which they provide Internet access service and block any traffic that does not comply with expected source addresses. Service Providers typically assign customers addresses from their own address space, or if the customer has their own address space, the service provider can ask for these address ranges at provisioning. (Network Operators may not be able to comply with this practice on links to upstream/downstream providers or peering links, since the valid source address space is not known).
Network Type(s) Cable; Internet/Data; Wireless; Wireline
Industry Role(s) Service Provider
Keyword(s) Cyber Security;Intrusion Detection;Network Provisioning;
Reference/Comments IETF rfc3013 sections 4.3 and 4.4 and NANOF ISP Resources.