Security Analysis of the MPLS Label Distribution Protocol
نویسندگان
چکیده
Since its inception more than a decade ago, multiprotocol label switching (MPLS) has become one of the fastest-growing telecommunications infrastructure technologies. The speed, flexibility, sophisticated traffic management and cost savings offered by MPLS have prompted service providers to converge existing and new technologies onto common MPLS backbones. Indeed, much of the world’s data, voice communications, video traffic and military applications traverse an MPLS core at some point. The rapid adoption of MPLS raises significant concerns – primarily because of the dependence of critical communication services on a technology that has yet to undergo significant security testing. This paper examines security issues associated with the Label Distribution Protocol (LDP), which is the primary route construction protocol in MPLS networks. Our analysis has identified ten attacks that exploit weaknesses in the LDP specification: six attacks that disrupt service and four that divert traffic from intended routes. Details of the attacks are presented along with suggested mitigation strategies and security postures.
منابع مشابه
Comparative Analysis of MPLS Signaling Protocols
MPLS is the pioneer in Service Provider Networks. Every service provider use MPLS in its core network for fast label switching. This paper explains MPLS and its signaling protocols i.e. LDP, CR-LDP, RSVP, RSVP-TE. This paper explains every signaling protocol that is used in Multiprotocol Label Switching environment. This paper explains differences between MPLS signaling protocols on the basis o...
متن کاملAn Overview of MPLS and Constraint Based Routing
Multiprotocol Label Switching provides a virtual path capability between packet (label) switches to efficiently carry differentiated services across the Internet. Additionally, MPLS has been enhanced with the capability to precisely engineer traffic tunnels to avoid congestion and utilize all available bandwidth in an efficient manner. This paper provides an extensive resource, serving the moti...
متن کاملInternet Engineering Task Force (ietf) Multipoint Label Distribution Protocol In-band Signaling in a Virtual Routing and Forwarding (vrf) Table Context
An IP Multicast Distribution Tree (MDT) may traverse both label switching (i.e., Multiprotocol Label Switching, or MPLS) and nonlabel switching regions of a network. Typically, the MDT begins and ends in non-MPLS regions, but travels through an MPLS region. In such cases, it can be useful to begin building the MDT as a pure IP MDT, then convert it to an MPLS Multipoint Label Switched Path (MP-L...
متن کاملIPSec and MPLS, (Even Better Together)
........................................................................................................................................... 1 IP SECURITY (IPSEC).......................................................................................................................... 1 MULTI-PROTOCOL LABEL SWITCHING (MPLS) ............................................................................
متن کاملA Framework for Multi-Protocol Label Switching (MPLS) Operations and Management (OAM)
Status of This Memo This memo provides information for the Internet community. It does not specify an Internet standard of any kind. Distribution of this memo is unlimited. Abstract This document is a framework for how data plane protocols can be applied to operations and maintenance procedures for Multi-Protocol Label Switching (MPLS). The document is structured to outline how Operations and M...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010