@techreport{wang-bmwg-measure-meth-ip-spoofing-00, number = {draft-wang-bmwg-measure-meth-ip-spoofing-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-wang-bmwg-measure-meth-ip-spoofing/00/}, author = {Shuai Wang and Dan Li and Ruifeng Li and Qian Cao}, title = {{Methods for Remotely Measuring IP Spoofing Capability}}, pagetotal = 16, year = 2024, month = apr, day = 10, abstract = {This document summarizes and standardizes methods for remotely measuring a network's IP spoofing capability. For outbound spoofing capability measurement, i.e., whether the network allows IP spoofing traffic to be sent from inside the network to the outside of the network, DNS traceroute can be used to check whether spoofed packets are generated in the network and sent to outside of the network. For inbound spoofing capability measurment, i.e., whether the network allows IP spoofing traffic from the outside the network to arrive inside, DNS resolver and ICMPv6 rate limiting mechanism can be utilized to check whether spoofed packets are received by devices in the network.}, }