14
Mitigating spoofing and replay attacks in MPLS-VPNs using label- hopping with TicToc Shankar Raman Balaji Venkat Gaurav Raina

Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

  • Upload
    gypsy

  • View
    56

  • Download
    0

Embed Size (px)

DESCRIPTION

Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc. Shankar Raman Balaji Venkat Gaurav Raina. Outline. MPLS VPN Security Issues. Secure Control Plane Exchange. Label hopping applied to data plane. Tic-Toc based Scheme. Control plane algorithms for PEne. - PowerPoint PPT Presentation

Citation preview

Page 1: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Shankar RamanBalaji VenkatGaurav Raina

Page 2: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Outline

Page 3: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

MPLS VPN Security Issues

Page 4: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Secure Control Plane Exchange

Page 5: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Label hopping applied to data plane

Page 6: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Tic-Toc based Scheme

Page 7: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Control plane algorithms for PEne

Page 8: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Control plane algorithms for PEfa

Page 9: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Data Plane Algorithm for PEfa

Page 10: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Data Plane Algorithm for PEne

Page 11: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Avoiding replay attacks

• Exchange the seed• Use Pseudo Random Number Generation

algorithm• Use the Random Number generated to choose

the labels at various time slices

Page 12: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Simulation and Implementation

Page 13: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

Conclusion

Page 14: Mitigating spoofing and replay attacks in MPLS-VPNs using label-hopping with TicToc

QUESTIONS?Thank you