DocumentCode
687794
Title
Securing the LISP map registration process
Author
Montero, D. ; Siddiqui, M.S. ; Serral-Gracia, R. ; Masip-Bruin, X. ; Yannuzzi, M.
Author_Institution
Adv. Network Archit. Lab. (CRAAX), Tech. Univ. of Catalonia (UPC), Vilanova i la Geltru, Spain
fYear
2013
fDate
9-13 Dec. 2013
Firstpage
2145
Lastpage
2151
Abstract
The motivation behind the Locator/Identifier Separation Protocol (LISP) has shifted over time from routing scalability issues in the core Internet to a set of use cases for which LISP stands as a technology enabler. Among these are the mobility of physical and virtual appliances without breaking their TCP connections, seamless migration and fast deployments of IPv6, multihoming, and data-center applications. However, LISP was born without security, and therefore is susceptible to attacks in its control-plane. The IETF´s LISP working group has recently started to work in this direction, but the protocol still lacks end-to-end mechanisms for securing the overall registration process on the mapping system. In this paper, we address this issue and propose a solution that counters the attacks. We have deployed LISP in a real testbed, and compared the performance of our proposal with current LISP implementations, in terms of both messaging and packet size overhead. Our preliminary results prove that our solution offers much higher security with minimum overhead.
Keywords
Internet; computer network security; transport protocols; IPv6; Internet core; LISP map registration process security; TCP connections; data-center applications; locator-identifier separation protocol; mapping system; physical appliances; routing scalability; virtual appliances; Authorization; Cryptography; Next generation networking; Proposals; Registers; Servers; Internet; LISP; Loc/ID split; routing; security;
fLanguage
English
Publisher
ieee
Conference_Titel
Global Communications Conference (GLOBECOM), 2013 IEEE
Conference_Location
Atlanta, GA
Type
conf
DOI
10.1109/GLOCOM.2013.6831392
Filename
6831392
Link To Document