BCP 38 (source address validation)

term

ISP & telecomsecurity

The practice of a network verifying that packets leaving it carry source addresses that actually belong to it, and dropping those that do not - blocking address forgery at the point where it originates.

It is the reason reflection attacks are possible at scale, and its adoption problem is economic rather than technical. A network that filters its own customers' forged packets protects strangers from attacks it will never see, and gains nothing measurable on its own dashboards. The guidance is from the 1990s, uncontroversial, and still not universal - which makes it the clearest case in networking of a control whose beneficiaries and implementers are different people.

Also known as: rfc 2827, anti-spoofing, ingress filtering, source address validation

All glossary entries