FYI. The U.S. Public Safety and Homeland Security Bureau released a Public Notice on Friday (copied below), seeking comment on the “implementation and effectiveness of the CSRIC III recommendations”.

Comments are due by September 26. Some folks here may wish to send the FCC comments on this, especially areas pertaining to preventing IP address spoofing.

- Jason

DA 14-1066 Released: July 25, 2014


In March 2012, the FCC’s third Communications Security, Reliability and Interoperability Council (CSRIC III)1 unanimously adopted voluntary recommendations for Internet service providers (ISPs) to combat three major cybersecurity threats: (1) botnet attacks; (2) domain name fraud; and (3) Internet route hijacking.2 Among other stakeholders, leading ISPs participated in the development of these recommendations and publicly committed to implementing them.3 The recommendations included voluntary measures in three areas: an Anti-Bot Code of Conduct to mitigate the proliferation of distributed denial of service (DDoS) attacks,4 steps to better secure the Domain Name System (DNS) through incremental implementation of DNSSEC, and steps to strengthen the security of the Internet’s inter-domain routing infrastructure.5

CSRIC III also recommended that the FCC encourage ISPs to implement source-address filtering topreventattackersfromspoofingIPaddressestolaunchDDoSattacks. Specifically,CSRIC recommended that the FCC encourage implementation of the following best current practices (BCPs) to mitigate this risk:6

  1. 1) BCP 38/RFC 2827 – Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing;7 and

  2. 2) BCP 84/RFC 3704 – Ingress Filtering for Multi-homed Networks.8

All CSRIC best practices are available on the Commission’s website in a searchable database.9

Since CSRIC III adopted these important recommendations, stakeholders have not yet provided the FCC’s Public Safety and Homeland Security Bureau (Bureau) information regarding their implementation that is sufficient for a meaningful understanding of either their effectiveness or lessons learned from implementation. Meanwhile, the vulnerabilities these recommendations were intended to address continue to be exploited.10 For example, recent DDoS attacks of unprecedented scale11 add to the urgency of ISPs’ implementation of CSRIC recommendations or of alternative approaches that ISPs believe are superior to the CSRIC recommendations.

Request for Comment

By this Public Notice, the Bureau seeks comment from ISPs, the Internet community, consumer organizations, and the broader public on the implementation and effectiveness of the CSRIC III recommendations and/or alternatives that stakeholders have developed since the time of the CSRIC’s original work to address these challenges.

The purpose of this Public Notice is to promote a robust, stakeholder-driven discourse drawing on broad perspectives from throughout the cyber ecosystem to provide the communications sector and the Commission new information, insights and situational awareness regarding innovative solutions to these

Federal Communications Commission 445 12th St., S.W.
Washington, D.C. 20554


News Media Information 202 / 418-0500 Internet: http://www.fcc.gov TTY: 1-888-835-5322

particular cyber risks. To the extent that companies or stakeholders may prefer that their submissions remain confidential, we intend to protect the confidentiality of submissions according to the requests and consistent with FCC rules, as described below. This inquiry is part of the Commission’s effort to develop effective and proactive private sector-driven cyber risk management;12 in particular, it complements and supports ongoing work in CSRIC IV to create measurable, accountable cyber assurances across a wide variety of IP-based communications technologies and services.13

The Bureau seeks public comment on the implementation status and effectiveness of these voluntary recommendations, or alternatives, by ISPs and other members of the Internet community. We are particularly interested in comment on the following questions as they relate to the four broad areas of CSRIC’s previous best practices and recommendations cited above:

  1. What progress have stakeholders made in implementing the recommendations?

  2. What barriers have stakeholders encountered in implementing the recommendations?

  3. What significant success stories or breakthroughs have been achieved in implementing the recommendations?

  4. What are stakeholders’ views and/or plans for full implementation of the recommendations?

  5. How effective are the recommendations at mitigating cyber risk when they have been

implemented? Given the experiences gained in the past two years, are there alternatives to full implementation that could be more effective than full implementation at mitigating cyber risk risks posed by botnets, DNS vulnerabilities, routing infrastructure vulnerabilities, and source address spoofing? On what basis do stakeholders believe that these alternatives are more effective than the CSRIC III recommendations? Do stakeholders undertake qualitative or quantitative evaluations of the effectiveness of these various approaches, or both?

Comment Submission

Interested parties are invited to comment by September 26, 2014. Please submit comments or meeting requests by email directly to the Associate Bureau Chief for Cybersecurity and Communications Reliability, Jeffery Goldthorp, at jeffery.goldthorp@fcc.gov, with a copy to the Deputy Chief of the Bureau’s Cybersecurity and Communications Reliability Division, Lauren Kravetz, at lauren.kravetz@fcc.gov.

Requests for confidential treatment of information submitted should follow the procedures set forth in section 0.459 of the Commission’s rules, under which all submissions with an appropriate request for confidential treatment will be treated as presumptively confidential pending a ruling on the request. Additionally, upon request and on a case-by-case basis, the Bureau may accommodate classified comment submissions or discussions.

Alternatively, those who desire to submit comments in hard copy only should submit an original and one copy of each set of comments. Hard copy comments can be sent by hand or messenger delivery, by commercial overnight courier, or by first-class or overnight U.S. Postal Service mail. All such submissions should be addressed to the Commission’s Secretary, Office of the Secretary, Federal Communications Commission and reference DA 14-1066.

  *  All hand-delivered or messenger-delivered paper submissions for the Commission’s Secretary must be delivered to FCC Headquarters at 445 12th St., SW, Room TW-A325, Washington, DC 20554. Delivery hours are 8:00 a.m. to 7:00 p.m. All hand deliveries must be held together with rubber bands or fasteners. Any envelopes and boxes must be disposed of before entering the building.

  *  Commercial overnight mail (other than U.S. Postal Service Express Mail and Priority Mail) must be sent to 9300 East Hampton Drive, Capitol Heights, MD 20743.


 U.S. Postal Service first-class, Express, and Priority mail must be addressed to 445 12th Street, SW, Washington DC 20554.

To request materials in accessible formats for people with disabilities (braille, large print, electronic files, audio format), send an e-mail to fcc504@fcc.gov or call the Consumer & Governmental Affairs Bureau at 202-418-0530 (voice), 202-418-0432 (tty).

For further information, contact Jeffery Goldthorp, at jeffery.goldthorp@fcc.gov or (202) 418- 1096 or Lauren Kravetz, at lauren.kravetz@fcc.gov or (202) 418-7944.

– FCC –

Interesting RFCs. Out of curiosity: do (many) routers already support the necessary ingress filter features to support these RFCs?

Kind regards,

Pieter Hulshoff


    It is a few million$ in man hours thou.

    ( Not necessary spent, but budgeted )

    And still no BCP38 recommendation.

    I wonder:

        1. If they taught of it;

        2. What was their process to not include it;

    Oh well.