@techreport{li-opsawg-stateful-copp-00, number = {draft-li-opsawg-stateful-copp-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-li-opsawg-stateful-copp/00/}, author = {Zhiqiang Li and Zongpeng Du and Junjie Wang and Wei Cheng and Guoying Zhang and Xun Sun and Chunhao Zhao}, title = {{Stateful Control Plane Policing}}, pagetotal = 8, year = 2026, month = jul, day = 4, abstract = {Control Plane Policing (CoPP), as described in RFC 6192, classifies control-plane-destined traffic using static packet header fields. This static classification cannot distinguish legitimate protocol traffic from attack traffic that matches the same header-based rules. This document specifies Stateful CoPP, an operational practice in which the router's runtime protocol state -- including configured peer identities, session state, and expected ingress interfaces -- is incorporated into CoPP classification. Stateful CoPP allows confirmed legitimate traffic to receive preferential access to control plane CPU resources under attack conditions.}, }