DocumentCode
3063813
Title
Analyzing failures and attacks in Map & Encap protocols
Author
Yan, He ; Kambhampati, Vamsi ; Massey, Dan ; Pei, Dan
Author_Institution
Colorado State Univ., Fort Collins, CO, USA
fYear
2010
fDate
5-5 Oct. 2010
Firstpage
19
Lastpage
24
Abstract
This paper examines failures and attacks in Map & Encap routing protocols. In Map & Encap, a packet is routed to an encapsulator, which maps the destination address to a decapsulator, and encapsulates the packet. This important and growing class of protocols, ranging from widely used MPLS VPNs to future routing architectures such as LISP, introduce new problems and challenges for handling failures and attacks. To capture fundamental components, we introduce a Simple Map & Encap Protocol (SMEP). Some failure handling approaches from traditional routing protocols also apply in SMEP, but these approaches alone are insufficient. SMEP design choices, and mapping dissemination in particular, have a large impact on whether new techniques are needed. In some cases, the control plane alone cannot adequately handle failures without support from the data plane and attacks can be much harder to diagnose. The results identify new potential failures and attacks and can help designers improve Map & Encap protocol robustness. We illustrate the benefits of our work by analyzing two very different types of Map & Encap protocols, MPLS-VPN and LISP.
Keywords
data encapsulation; multiprotocol label switching; packet radio networks; routing protocols; LISP; MPLS VPN; Map & Encap protocols; SMEP; attacks; decapsulator; encapsulator; failures; packet routing; routing protocols; simple map & encap protocol; Convergence; Multiprotocol label switching; Routing; Routing protocols; Topology; Virtual private networks;
fLanguage
English
Publisher
ieee
Conference_Titel
Secure Network Protocols (NPSec), 2010 6th IEEE Workshop on
Conference_Location
Kyoto
Print_ISBN
978-1-4244-8916-9
Type
conf
DOI
10.1109/NPSEC.2010.5634453
Filename
5634453
Link To Document