@Clive Robinson
By definition a defense is something you do to protect your self.
No, it isn't. Perhaps your British definition of the word is as wacky as the spelling? A defense need not be active or personalized. A banking website's encryption is a defense against my account being hacked. A distant levee may be a defense against my land being flooded. The airbag in my car is a defense against injury in an accident. There are countless ways I am defended that are not the result of any action on my part.
You have no control over what Russia does in the way of connecting or not connecting to the Internet. Likewise you have no control over what attackers do in response to what Russia does.
Immaterial. I have no control over mountains or oceans, but they are still barriers that defend me from potential attackers. I have no control over armies or navies, but some of them protect my rights just as certainly as others seek to take them away. Please think more deeply about the matter.
So like it or not politics is intruding like the proverbial camels nose.
It's not an issue of love or hate. As I said, I simply do not care about those things. The actions I take against abuse do not rely on the abuser cooperating with me or even acting in their own best interest. Until the day comes when Russia (or Iran or any other foreign network) actually provides me something of value online, their connectivity or lack of connectivity is no concern of mine. As it stands, they are the source of attacks, and thus a net negative, and thus it is to my advantage if they self-select to withdraw from the open Internet. @SpaceLifeForm
Consider: I'm a very large backbone network
But you are not. I'm pretty sure 100% of the attacks I have coming in are not operating at that high a level of compromise. I just don't do anything that would draw enough attention to put resources in motion that result in rerouting major portions of the Internet to come after me. Save those fanciful notions for Bruce's next movie plot contest.
Why do you believe that I can not control those tcp sessions?
Because your exposure in doing so would be too great for the rewards. Like I said, I see things like scans for PHP exploits. I see things like scans for Raspberry Pi's connected to the Internet that are still using the default account password. Even if I were vulnerable to such attacks, all you'd end up getting ahold of is a basic server that is a cookie cutter copy of just about what every cloud provider is offering.
Why would you believe that I can not forge the source ip address, and because I can control the route, still want to believe the socket actually reflects reality?
I'll believe it when I see it. At this point, I have no evidence that the routing of any random host like mine is being manipulated. When it has happened, it's been on the scale of targeting the Google's of the world, not just to make it look like a common dictionary attack on a low-end host falsely came from China (or wherever).
I can make your socket end look like my socket end came from *ANYWHERE*.
No, you can't. Prove me wrong. Let me know which log file to look at. 89347a11d99e7b8727a9abc302ad6636e664ee0727a6643f71c8f21e02a3305b