BGP FlowSpec is a new method defined in RFC 5575 that can be used to prevent DDoS attacks in an automated fashion by leveraging BGP. The BGP flow specification (FlowSpec) feature allows you to automatically propagate the filtering and policing functionality to service a provider's upstream BGP peer routers. This will mitigate the effects of a DDoS attack on your network. Most vendors still have this implementation in their roadmaps. For support, please check with ISP before implementing this solution.
BGP FlowSpec uses a more granular approach and provides you with the flexibility to effectively construct instructions to match a particular data flow with source, destination, L4 parameters, and packet specifics, such as length, and fragment. In this example, the customer router (which is the FlowSpec router) advertises these flows to the ISP edge routers. These...