首页> 外文会议>Network Traffic Measurement and Analysis Conference >TNT, Watch me Explode: A Light in the Dark for Revealing MPLS Tunnels
【24h】

TNT, Watch me Explode: A Light in the Dark for Revealing MPLS Tunnels

机译:TNT,看着我爆炸:透露MPLS隧道的黑暗中的光线

获取原文

摘要

Internet topology discovery aims at analyzing one of the most complex distributed system currently deployed. Usually, it relies on measurement campaigns using hop-limited probes sent with traceroute. However, this probing tool comes with several limits. In particular, some MPLS clouds might obfuscate collected traces. Thus, the resulting Internet maps, the inferred properties, and the graph models are incomplete and inaccurate.In this paper, we introduce TNT (Trace the Naughty Tunnels), an extension to Paris traceroute for revealing, or at least detect, all MPLS tunnels along a path. First, along with traceroute and ping probes, TNT looks for hints indicating the presence of hidden tunnels. Those hints are peculiar patterns in the resulting output, e.g., significant TTL shifts or duplicate IP addresses. Second, if those hints trigger alarms, TNT launches additional dedicated probing for possibly revealing hidden tunnels. We use GNS3 to reproduce, verify, and understand the limits and capabilities of TNT in a controlled environment. We also calibrate the thresholds at which alarms are triggered through a dedicated measurement campaign. Finally, we deploy TNT on the Archipelago platform and provide a quantified classification of MPLS usage. All our results, including the data, the code, and the emulation configurations, are fully and publicly available.
机译:Internet拓扑发现旨在分析目前部署的最复杂的分布式系统之一。通常,它依赖于使用与Traceroute发送的跳跃有限探针的测量活动。但是,该探测工具具有几个限制。特别是,某些MPLS云可能会混淆收集的痕迹。因此,由此产生的互联网映射,推断的属性和图形模型是不完整和不准确的。在本文中,我们介绍了TNT(追踪顽皮的隧道),对Paris Traceroute的扩展进行了揭示,或者至少检测到所有MPLS隧道沿着一条路。首先,以及Traceroute和Ping探针,TNT寻找指示隐藏隧道的存在的提示。这些提示是由此产生的输出中的特殊模式,例如,显着的TTL偏移或重复的IP地址。其次,如果那些提示触发警报,TNT会推出额外的专用探测,以便可能揭示隐藏的隧道。我们使用GNS3在受控环境中重现,验证和理解TNT的限制和功能。我们还校准通过专用测量活动触发警报的阈值。最后,我们在Archipelago平台上部署TNT,并提供MPLS使用量的量化分类。我们所有的结果,包括数据,代码和仿真配置,都完全可公开可用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号