Security Analysis of the MPLS Label Distribution Protocol

نویسندگان

  • Daniel Guernsey
  • Aaron Engel
  • Jonathan Butts
  • Sujeet Shenoi
چکیده

Since its inception more than a decade ago, multiprotocol label switching (MPLS) has become one of the fastest-growing telecommunications infrastructure technologies. The speed, flexibility, sophisticated traffic management and cost savings offered by MPLS have prompted service providers to converge existing and new technologies onto common MPLS backbones. Indeed, much of the world’s data, voice communications, video traffic and military applications traverse an MPLS core at some point. The rapid adoption of MPLS raises significant concerns – primarily because of the dependence of critical communication services on a technology that has yet to undergo significant security testing. This paper examines security issues associated with the Label Distribution Protocol (LDP), which is the primary route construction protocol in MPLS networks. Our analysis has identified ten attacks that exploit weaknesses in the LDP specification: six attacks that disrupt service and four that divert traffic from intended routes. Details of the attacks are presented along with suggested mitigation strategies and security postures.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Comparative Analysis of MPLS Signaling Protocols

MPLS is the pioneer in Service Provider Networks. Every service provider use MPLS in its core network for fast label switching. This paper explains MPLS and its signaling protocols i.e. LDP, CR-LDP, RSVP, RSVP-TE. This paper explains every signaling protocol that is used in Multiprotocol Label Switching environment. This paper explains differences between MPLS signaling protocols on the basis o...

متن کامل

An Overview of MPLS and Constraint Based Routing

Multiprotocol Label Switching provides a virtual path capability between packet (label) switches to efficiently carry differentiated services across the Internet. Additionally, MPLS has been enhanced with the capability to precisely engineer traffic tunnels to avoid congestion and utilize all available bandwidth in an efficient manner. This paper provides an extensive resource, serving the moti...

متن کامل

Internet Engineering Task Force (ietf) Multipoint Label Distribution Protocol In-band Signaling in a Virtual Routing and Forwarding (vrf) Table Context

An IP Multicast Distribution Tree (MDT) may traverse both label switching (i.e., Multiprotocol Label Switching, or MPLS) and nonlabel switching regions of a network. Typically, the MDT begins and ends in non-MPLS regions, but travels through an MPLS region. In such cases, it can be useful to begin building the MDT as a pure IP MDT, then convert it to an MPLS Multipoint Label Switched Path (MP-L...

متن کامل

IPSec and MPLS, (Even Better Together)

........................................................................................................................................... 1 IP SECURITY (IPSEC).......................................................................................................................... 1 MULTI-PROTOCOL LABEL SWITCHING (MPLS) ............................................................................

متن کامل

A Framework for Multi-Protocol Label Switching (MPLS) Operations and Management (OAM)

Status of This Memo This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This document is a framework for how data plane protocols can be applied to operations and maintenance procedures for Multi-Protocol Label Switching (MPLS). The document is structured to outline how Operations and M...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010