%% You should probably cite draft-cui-idr-content-filter-flowspec-03 instead of this revision. @techreport{cui-idr-content-filter-flowspec-01, number = {draft-cui-idr-content-filter-flowspec-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-cui-idr-content-filter-flowspec/01/}, author = {Yong Cui and Yujia Gao}, title = {{Packet Content Filter for BGP FlowSpec}}, pagetotal = 8, year = , month = , day = , abstract = {The BGP Flow Specification enables the distribution of traffic filter policies (traffic filters and actions) via BGP, facilitating DDoS traffic filtering. However, the traffic filterer in FSv1 and FSv2 predominantly focuses on IP header fields, which may not adequately address new types of DDoS attack traffic characterized by constant patterns within the packet content. This document introduces a new flow specification filter type designed for packet content filtering. The match field includes otype, offset value, content-length, and content, encoded in the Flowspec NLRI. This new filter aims to augment DDoS defense capabilities.}, }