DocumentCode :
3063813
Title :
Analyzing failures and attacks in Map & Encap protocols
Author :
Yan, He ; Kambhampati, Vamsi ; Massey, Dan ; Pei, Dan
Author_Institution :
Colorado State Univ., Fort Collins, CO, USA
fYear :
2010
fDate :
5-5 Oct. 2010
Firstpage :
19
Lastpage :
24
Abstract :
This paper examines failures and attacks in Map & Encap routing protocols. In Map & Encap, a packet is routed to an encapsulator, which maps the destination address to a decapsulator, and encapsulates the packet. This important and growing class of protocols, ranging from widely used MPLS VPNs to future routing architectures such as LISP, introduce new problems and challenges for handling failures and attacks. To capture fundamental components, we introduce a Simple Map & Encap Protocol (SMEP). Some failure handling approaches from traditional routing protocols also apply in SMEP, but these approaches alone are insufficient. SMEP design choices, and mapping dissemination in particular, have a large impact on whether new techniques are needed. In some cases, the control plane alone cannot adequately handle failures without support from the data plane and attacks can be much harder to diagnose. The results identify new potential failures and attacks and can help designers improve Map & Encap protocol robustness. We illustrate the benefits of our work by analyzing two very different types of Map & Encap protocols, MPLS-VPN and LISP.
Keywords :
data encapsulation; multiprotocol label switching; packet radio networks; routing protocols; LISP; MPLS VPN; Map & Encap protocols; SMEP; attacks; decapsulator; encapsulator; failures; packet routing; routing protocols; simple map & encap protocol; Convergence; Multiprotocol label switching; Routing; Routing protocols; Topology; Virtual private networks;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Network Protocols (NPSec), 2010 6th IEEE Workshop on
Conference_Location :
Kyoto
Print_ISBN :
978-1-4244-8916-9
Type :
conf
DOI :
10.1109/NPSEC.2010.5634453
Filename :
5634453
Link To Document :
بازگشت