Securing the MPLS control plane

被引:0
|
作者
Palmieri, F [1 ]
Fiore, U [1 ]
机构
[1] Univ Naples Federico II, Ctr Serv Didatt Sci, I-80126 Naples, Italy
关键词
MPLS; strong authentication; integrity; label distribution; signaling;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As the Internet continues to grow, it faces an increasingly hostile environment and consequently, the need for security in network infrastructure is stronger than ever. In this scenario the Multi-Protocol Label Switching (MPLS) emerging paradigm, seems to be the cornerstone for developing most of the next generation network infrastructure-level services in the Internet. Unfortunately, due to the lack of a scalable means of verifying the authenticity and legitimacy of the control plane traffic in an MPLS domain, almost all the existing MPLS control and signaling protocols are extremely vulnerable to a variety of malicious attacks both in theory and in practice and communication between peer routers speaking the above common protocols is subject to active and passive forgery, hijacking and wiretapping activities. In this paper, we propose a robust framework for MPLS-based network survivability against security threats, by making the MPLS control and signaling protocols more secure. Our design goals include integrity safeguarding, protection against replay attacks, and gradual deployment, with routers not supporting authentication breaking the trust chain but operating undisturbed under any other respect.
引用
收藏
页码:511 / 523
页数:13
相关论文
共 50 条
  • [1] Performance analysis of the control and forwarding plane in an MPLS router
    Adami, D
    Carlotti, N
    Giordano, S
    Pagano, M
    Repeti, M
    [J]. OPTICAL NETWORKS AND TECHNOLOGIES, 2005, 164 : 254 - 262
  • [2] Cooperation of control and management plane for provisioning in MPLS networks
    Grampin, E
    Serrat, J
    [J]. Integrated Network Management IX: MANAGING NEW NETWORKED WORLDS, 2005, : 281 - 294
  • [3] Securing the global information grid routing control plane
    Chao, Victor
    Christou, Christos A.
    Tarr, Julie
    [J]. MILCOM 2006, VOLS 1-7, 2006, : 942 - 948
  • [4] Security Bootstrapping for Securing Data Plane and Control Plane in Named Data Networking
    Park, Chang-Seop
    Park, Wang-Seok
    Woo, Samuel
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (03): : 3765 - 3781
  • [5] MPLS-Kit: An MPLS Data Plane Toolkit
    Vanerio, Juan
    Schmid, Stefan
    Schou, Morten Konggaard
    Srba, Jiri
    [J]. PROCEEDINGS OF THE 2022 IEEE 11TH INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (IEEE CLOUDNET 2022), 2022, : 49 - 54
  • [6] Securing MPLS networks with multi-path routing
    Alouneh, Sahel
    En-Nouaary, Abdeslam
    Agarwal, Anjah
    [J]. INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY, PROCEEDINGS, 2007, : 809 - +
  • [7] Automated Permission Model Generation for Securing SDN Control-Plane
    Kang, Heedo
    Yegneswaran, Vinod
    Ghosh, Shalini
    Porras, Phillip
    Shin, Seungwon
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 1668 - 1682
  • [8] Fast restoration on network control plane established through photonic MPLS routers
    Shimano, K
    Sahara, A
    Noguchi, K
    Koga, M
    Takigawa, Y
    Sato, K
    [J]. IEICE TRANSACTIONS ON COMMUNICATIONS, 2003, E86B (05) : 1522 - 1529
  • [9] Deployment and Interoperability of the Phosphorus Grid Enabled GMPLS (G2MPLS) Control Plane
    Escalona, E.
    Zervas, G.
    Nejabati, R.
    Simeonidou, D.
    Markidis, G.
    Tzanakaki, A.
    Carrozzo, G.
    Ciulli, N.
    Belter, B.
    Binczewski, A.
    [J]. CCGRID 2008: EIGHTH IEEE INTERNATIONAL SYMPOSIUM ON CLUSTER COMPUTING AND THE GRID, VOLS 1 AND 2, PROCEEDINGS, 2008, : 716 - +
  • [10] MPLS ATCC: An active traffic and congestion control mechanism in MPLS
    Zhang, ZQ
    Shao, X
    Ding, W
    [J]. 2001 INTERNATIONAL CONFERENCES ON INFO-TECH AND INFO-NET PROCEEDINGS, CONFERENCE A-G: INFO-TECH & INFO-NET: A KEY TO BETTER LIFE, 2001, : B222 - B227