[saag] DOTS Summary

The DDOS Open Threat Signaling (DOTS) BOF [1] met on Tuesday.  This non-working group forming BOF discussed how on-premises mitigation devices could communicate threat and telemetry data with a service provider for improved mitigation.  Two draft [2] [3] and a panel of vendors helped frame the discussion.

There was consensus that the on-premises mitigation devices should communicate capabilities, telemetry, and threat data to the service provider.  The service provider should push down policy and describe what mitigation it is performing.  There was also consensus that this is work that the IETF should perform.

The next steps from the participants’ comments leaned towards a new working group.  Please continue the conversation and add your perspective on the mailing list [4].
[1] http://www.ietf.org/proceedings/92/slides/slides-92-dots-2.pptx
[2] draft-teague-open-threat-signaling-00
[3] draft-fu-ipfix-network-security-00
[4] https://www.ietf.org/mailman/listinfo/dots