【24h】

Malicious MPLS Policy Engine Reconnaissance

机译:恶意MPLS策略引擎侦察

获取原文

摘要

Multi-Protocol Label Switching (MPLS) is widely used on telecommunications carrier and service provider backbone networks, complex network infrastructures, and also for the interconnection of distributed sites requiring guaranteed quality of service (QoS) and service levels such as the financial services sector, government and public safety, or control networks such as the electric power grid. MPLS is a policy-based system wherein router behaviour is determined not only by the base protocols, but also by a set of further policies that network operators will typically wish not to reveal. However, sophisticated adversaries are known to conduct network reconnaissance years before executing actual attacks, and may also wish to conduct deniable attacks that may not be visible as such that appear as service degradation or which will cause re-configuration of paths in the interest of the attacker. In this paper we therefore describe a probing algorithm and a model of MPLS state space allowing an adversary to learn about the policies and policy state of an MPLS speaker. In spite of the restrictions on the adversary, our probing algorithm revealed the policy states of non-directly connected routers. Also, we analyse the confirmed information using a Bayesian network and provide simulative validation of our findings.
机译:多协议标签交换(MPLS)广泛用于电信运营商和服务提供商的骨干网,复杂的网络基础设施,以及用于要求保证服务质量(QoS)和服务水平的分布式站点之间的互连,例如金融服务部门,政府和公共安全或电网等控制网络。 MPLS是一种基于策略的系统,其中路由器的行为不仅取决于基本协议,还取决于网络运营商通常不希望透露的其他策略集。但是,众所周知,精明的对手会在执行实际攻击之前进行网络侦察多年,并且还可能希望进行可拒绝的攻击,这些攻击可能不可见,从而导致服务质量下降,或者会出于利益考虑而重新配置路径。攻击者。因此,在本文中,我们描述了MPLS状态空间的探测算法和模型,从而使对手可以了解MPLS发言人的策略和策略状态。尽管有对手的限制,我们的探测算法仍显示了非直接连接路由器的策略状态。此外,我们使用贝叶斯网络分析已确认的信息,并对我们的发现进行模拟验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号