skip to content

As a hosting provider, how do you justify funding source-address validation that protects other networks?

level: principalimportance: nice to knowfreq 30%

answer

  1. concentrated cost, diffuse benefit
  2. only the origin knows the legitimate range
  3. reputation and abuse labour are line items
  4. one benefit you do keep, internally
  5. commit at the edge, scope it honestly

basics

~10 s

Stop arguing it on altruism and name what you capture: your address space's reputation, recurring abuse-handling cost, peer and contract pressure, and the customer-to-customer forgery the same validation stops inside your own estate.

solid answer

~60 s

The technical case is settled and loses on its own. Only the network where a packet originates knows which addresses its customer may legitimately use, so only it can validate cheaply — and every forged packet it drops would have harmed a stranger. That is a textbook externality, which is why the practice has been recommended for decades and is still not universal. What actually moves a commercial owner is the part of the benefit you do capture: your prefixes ending up on other people's blocking lists, which hurts your legitimate customers; abuse-desk and takedown labour as a recurring line item; transits and peers who now ask about it, and published industry norm programmes that make it a box customers and tenders expect ticked; the fact that spoof-tolerant networks attract exactly the low-margin, high-churn customers you do not want; and the direct win that the same edge validation stops one customer forging another's address, or forging your own infrastructure's. Then scope the commitment honestly to the customer edge and say plainly where it does not apply.

go deeper

for a junior

Take away the core fact: the only place a forged source is cheap to catch is the network the packet leaves from, and that network is not the one being harmed.

for a middle

Be able to explain why validation is easy at a customer port and unreliable in the core, using asymmetric and multi-homed routing as the reason.

for a senior

Demonstrate that you would scope the commitment to where it is reliable, plan the exceptions for customers with their own address space, and refuse to overclaim the result.

for a principal

Own the economics: name the externality, then win the funding on reputation, abuse cost, interconnect and tender pressure, and the internal isolation the same control delivers.

## Why the argument is hard, stated fairly Source-address validation at the network edge has been the published recommendation since the late 1990s — BCP 38 (RFC 2827) is the canonical statement, and later industry norm programmes for network operators carry anti-spoofing as one of their headline actions. It is not a hard technique and it is not expensive. It is nevertheless under-deployed, and the reason is economic rather than technical. The party that can validate cheaply is the network where the packet originates, because only it knows which ranges it assigned to which customer port. The party that suffers is somebody else's customer, on somebody else's network, possibly on another continent. So the network that spends the money receives essentially none of the direct benefit, while the network that receives the benefit cannot buy it at any price. Costs are concentrated and benefits are diffuse, which is the standard shape of an under-supplied public good. Anyone who presents this to a commercial owner as *the right thing to do* has already lost the meeting. ## Why nobody else can solve it instead **Not the target.** A forged source address is indistinguishable, packet by packet, from a real one. The target sees traffic that claims to come from thousands of places and has no basis to decide which claims are true. **Not the core.** Away from the edge, routing is asymmetric and multi-homed: a legitimate packet can arrive over a link that is not the reverse of the path back to its source. Validation there produces false drops, which are customer-visible outages. The incentive asymmetry is brutal — permitting forgery is invisible to your own customers, while over-filtering generates tickets within minutes. **Not standards bodies alone.** The recommendation exists. Recommendations do not fund line items. ## The self-interested arguments that actually work 1. **Reputation of your address space.** Sustained abuse from your ranges gets those ranges filtered, rate-limited or blocked by other operators and platforms. The victims of that are your paying customers, who then call you. 2. **Abuse-handling as an operating cost.** Complaints, takedown requests, escalations from transits, emergency null-routing at unsociable hours — this is staff time with a real annual number attached, and it is the number to put in the paper. 3. **Peer and transit pressure.** Interconnect negotiations increasingly include questions about it, and published norm programmes give the counterparty an easy checklist. Being unable to answer is a commercial position, not a neutral one. 4. **Contracts and tenders.** Enterprise and public-sector buyers ask. A missing answer costs deals in a way a filter never costs anything. 5. **Adverse selection.** A network known to forward anything attracts customers who want to forward anything. Those customers are low-margin, high-support and short-lived, and they degrade the asset in argument 1. 6. **The benefit you genuinely keep.** This is the one people forget and it is the strongest. The same validation at the customer edge stops one customer forging another customer's address inside your estate, and stops any customer forging the addresses of your own management and infrastructure. That is not altruism at all — it is internal isolation you would have to build some other way. ## Scope the commitment so it survives contact A promise you cannot keep is worse than no promise. Commit where the answer is knowable and the cost is one-time: the single-homed customer port, where the legitimate range is fixed at provisioning and the policy is applied as part of turn-up rather than as an incident response. Be explicit that transit and multi-homed interconnects are out of scope, and document the exception process for the customer who legitimately emits addresses outside the block you assigned — a customer with its own address space, or one carrying downstream networks of its own. Those exceptions are the real operational cost, and pretending they do not exist is how these programmes acquire a reputation for breaking things. ## Do not overclaim what it buys Edge validation constrains a customer to the addresses it was assigned. Within that range, a compromised machine can still forge its neighbours. So the correct claim is that you no longer emit forged traffic aimed at the rest of the internet, not that your network cannot produce a forged packet. Overstating it is how a programme loses credibility the first time somebody demonstrates otherwise. ## The framing that wins the room The attackers who depend on this are the cheapest actors in the category — people running published proof-of-concept code or paying a subscription for someone else's. They are not defeated by target hardening, because they are not attacking a target's defences; they are consuming a supply of networks willing to carry a lie. The supply is the product. Reducing it is one of the very few security investments that changes an attack's price globally rather than moving it somewhere else, and the honest pitch to an owner is that you are choosing to stop being part of the supply, for reasons that also happen to appear on your own balance sheet.

  • Why can the receiving network not solve this for itself?
    Because a forged source is indistinguishable from a real one in the packet. The receiver can see that traffic arrived claiming thousands of origins, but it has no basis to test any individual claim, and the addresses being claimed usually belong to innocent third parties whose real traffic it must keep accepting.
  • What is the honest limit of validating at the customer edge?
    It confines a customer to the addresses you assigned it; inside that block, a compromised machine can still claim its neighbours' addresses. So the defensible claim is that your network stops emitting forgeries aimed outward, not that it cannot produce a forged packet at all.
  • How would you handle a customer that legitimately sends traffic from addresses you did not assign?
    Treat it as a documented exception rather than a reason to abandon the policy. Customers with their own address space or downstream networks of their own genuinely emit other ranges, so record what they may source at provisioning and review it on change. Those exceptions are the real operating cost of the programme.

It is the upstream factory being asked to fit a filter. The cleaner water arrives at towns it will never bill, so the argument that closes it is never the river — it is the fines, the reputation, and the fact that the same filter keeps the factory's own intake clean.

saying these in an interview costs you the question

  • Argues the spend purely on altruism or good citizenship
  • Claims edge validation makes the network unable to spoof
  • Says the victim's network should filter it instead
  • Treats it as a transit or core problem rather than an edge one

context