Real BGP blackholing (RTBH) for single-router networks. No multihoming, no public ASN required. $59/mo, 14-day free trial, no card required, auto-approved.

6 points•jkalbfeld•1 day ago•8 comments•
Hey friends, I've been working on this idea since 2019, and wanted to share it and see who might be interested. I built a BGP network full of nodes that collect threat data, put it on a blockchain, and put it into a BGP community that anyone can peer with over GRE. The external network ASN is AS23026.

Basically, you sign up on the website -- you can create an account with your email or with peeringdb or a thoughtwave account, set up a private ASN and it spits out a router config that you can use to start blackholing routes. I have been using it for months now on my edge router (AS54380) and it has cut SSH attacks down drastically.

It doesn't do volumetric protection against DDoS, but it will give you protection against brute force attacks. It ingest spamhaus, a bunch of other feeds as well as fail2ban from participants and also our own attack intelligence.

It's $59/month after the two week trial, and you can cancel at any time. I have a support ticket system. Would love to get some feedback.

8 comments

smwabout 9 hours ago
I guess the real question here is what happens if my service _does_ get attacked by a volumetric DDoS? Do you immediately stop advertising?
jkalbfeldabout 6 hours ago
Since you wouldn't be running transit through us, the traffic would still reach you, and you can use uRPF to block it in-situ.
BrianGraggabout 6 hours ago
The statement above: It doesn't do volumetric protection against DDoS
112233about 8 hours ago
Hopefully upstream peers will use RPKI properly. It would be sad if this actually worked.
jkalbfeldabout 6 hours ago
RPKI is great, and I use it for everything except for two /24's that I got pre-ARIN. However, RPKI won't help with the situation where some kind of compromised host is worming its way through the internet running nmap against everything. Most of the IP addresses showing up in our dragnet are in fact announced by the very ISPs that own them. Most of these do not appear to be bogons.
BrianGraggabout 6 hours ago
I don't think RPKI will do anything to stop threats or DDOS attacks that happen currently. It should stop rogue route updates though.
RationPhantomsabout 9 hours ago
Your 4. is incorrect. Traffic does not get dropped upstream.
jkalbfeldabout 6 hours ago
You're right. I fixed the copy to clarify its functionality. The blackhole feed doesn't actually sit in your traffic path; it tells your own router what to drop by creating longer CIDRs. Traffic still reaches you over your real ISP connection same as always - your router just can't send an ACK reply back, so it kills the handshake and prevents brute force attacks. If you also set up uRPF (covered in our setup docs), it goes a step further and drops their packets on arrival instead of just failing your reply. In this case, since we're not a transit provider, preventing volumetric attacks can be a little bit tricky since we're not actually in your upstream. However, it is possible to ETL chain data and generate a filter list. I figured at this price point, volumetric protection is a little bit hard to implement.

Read the full thread on Hacker News →

Related stories