Changeoption82

option82  时间:2021-04-04  阅读:()
2009InfosysTechnologiesLimitedSANOGXIV2009InfosysTechnologiesLimitedSANOGXIVTacklingSpoofingAttacksinBroadbandAccessNetworksBharatJoshi(bharat_joshi@infosys.
com)PavanKurapati(pavan_kurapati@infosys.
com)RamakrishnaRaoDTV(ramakrishnadtv@infosys.
com)2009InfosysTechnologiesLimitedSANOGXIVAgendaSpoofing–What,WhyandHowTypesofuserconnectionsinBroadbandAccessConcentratorsTypesofspoofingHowtocollectdatatodoAnti-spoofinginAccessNetworkAnti-spoofingHowtorecoveranti-spoofingdataafterBACcrash/reboot2009InfosysTechnologiesLimitedSANOGXIVWhatisSpoofiingSpoofingisaprocesswherebyoneentitymasqueradesasanotherentityWhyisspoofingdoneSpoofingAbyBisdoneforvariouspurposesBseekstheprivilegesofABintendstohideitstracksAsanattackonAHowisspoofingdoneWeshallseeincomingslides2009InfosysTechnologiesLimitedSANOGXIVTheultimategoalofspoofingUnauthorizedServiceGetserviceonsomeoneelse'sexpenseLossofServiceonTargetMakesurethatthetargetdoesnotgetanyserviceDifficulttotracetheattackerMakesurethatpeoplecannotfindwhoattackedthem.
UnnecessarypacketscloggingthenetworkMakesurethatnobodygetsagoodservice.
SecondaryvictimPrimarytargetrespondstospoofpacketandoverwhelmthesourcewhichbecomessecondaryvictim.
2009InfosysTechnologiesLimitedSANOGXIVTypesofuserconnectionsforanIPbasedDSLAMBridgedIPRoutingRFC2684basedbridgedencapsulationbetweenEndUserandDSLAMDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fDynamicIPallocationusingDHCPPPPoE/APPPterminationinDSLAMIPallocationfromlocalpoolDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fIPoARFC2684basedroutedencapsulationbetweenEndUserandDSLAMDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fDynamicIPallocationusingDHCPL3DSLAMxDSLHomeHubxDSLHomeHubMPLSCloudPEPRouterPRouterBRASL3n/wDataCenterL3DSLAMInternetservices2009InfosysTechnologiesLimitedSANOGXIV6DSLAML3AxDSLHomeHubL3n/wDHCP2UnicastDISCOVER+Option82populatedwithRemote-ID/Circuit-ID1BroadcastDHCPDISCOVERUnicastDHCPOFFERwithoption82echoed3SendDHCPOFFERtothehostafterremovingoption8246UnicastREQUEST+Option82populatedwithRemote-ID/Circuit-ID5BroadcastDHCPREQUESTUnicastDHCPACKtotheclientwithoption827SendDHCPACKtothehostafterremovingoption828AddressallocationmechanismsforIPDSLAM–DHCP2009InfosysTechnologiesLimitedSANOGXIVTypesofuserconnectionsforaLayer2DSLAM1:1VLANsMapeveryuserconnectiontooneunique802.
1qbasedVLANNoneedofanyMAClearningofindividualhostsDownstreamtrafficmappingdonebasedonVLANsQinQorStackedVLANsAnouterServiceVLANidentifyingaspecificserviceisaddedDownstreammappingdonebasedoncombinationofCVLANandSVLANN:1TransparentBridgedVLANsMultipleusersmappedtoacommonVLANDownstreammappingdonebasedonVLANandDstMACcombinationMAClearningisrequiredforoperationL2DSLAMxDSLHomeHubxDSLHomeHubMPLSCloudPEPRouterPRouterBRASAccessAggregationDataCenterL2DSLAMInternetservices2009InfosysTechnologiesLimitedSANOGXIV8DSLAML2RAxDSLHomeHubBRASL3RAMetroDHCP2BroadcastDISCOVER+Option82populatedwithRemote-ID/Circuit-ID1BroadcastDHCPDISCOVER3UnicastDISCOVERwith'giaddr'populatedUnicastDHCPOFFERwithoption82echoed45BroadcastDHCPOFFERwithoption82andwithout'giaddr'SendDHCPOFFERtothehostafterremovingoption8268BroadcastREQUEST+Option82populatedwithRemote-ID/Circuit-ID7BroadcastDHCPREQUEST9UnicastREQUESTwith'giaddr'populatedUnicastDHCPACKtotheclientwithoption8210SendDHCPACKtothehostafterremovingoption8211AddressallocationmechanismsforL2DSLAM–DHCP2009InfosysTechnologiesLimitedSANOGXIV9DSLAML2RAxDSLHomeHubBRASL3RAMetroDHCPRADIUSPortEnabled1EAPOLStart2IdentityRequest3IdentityResponse4IdentityDetails5EAPMD5Challenge6MD5ChallengeResponse7AuthSuccess8AuthSuccess9DHCPAuthentication&AddressallocationmechanismsforL2DSLAM–DHCP+802.
1x2009InfosysTechnologiesLimitedSANOGXIV10DSLAMxDSLHomeHubBRASMetroRADIUS2PADI+IntermediateAgentpopulatedwithRemote-ID/Circuit-ID1PADIPADO+IntermediateAgentechoed35PADR6PADR+IntermediateAgentpopulatedwithRemote-ID/Circuit-IDPADS+IntermediateAgentechoed79PPPNegotiationsAuthentication&AddressallocationmechanismsforL2DSLAM-PPPoEPADOafterremovingagentinformationoption4PADSafterremovingagentinformationoption82009InfosysTechnologiesLimitedSANOGXIVTypeofSpoofingMACSpoofingIPSpoofingARPSpoofingControlprotocolinternalheaderspoofingPPPoEsession-idspoofingDHCPchaddr,ciaddr,relay-agent-informationoptionspoofing2009InfosysTechnologiesLimitedSANOGXIV12DSLAMAttackerChangeSrcMACaddressandfloodtrafficSimulates1000sofMACaddressatfasterratexDSLMACTablemaximumlimitreachedLegitimatetrafficdroppedduetoMACtableexhaustionChangingSourceMACaddresstoanillegitimateaddressAttackerxDSLMACI/FB2A2FloodtrafficwithbothMACAandMACBMACBLegitimatetrafficblockedMACAMACspoofing2009InfosysTechnologiesLimitedSANOGXIVIPspoofingChangingSourceIPaddresstoanillegitimateaddressAttackerxDSLIPBDoSattackonIPAIPASendtrafficwithIPAandMACBRepliesfloodedtoIPA12PingofDeathServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVARPspoofingRespond/sendARPResponsewithillegitimateIPaddressABCDARP:WhoisIPB1ARPReply:IamIPB:MACA2IPMACAABATrafficflowingtohostAARPTableABCDGratuitousARP:IamIPB:MACA1IPMACAABATrafficflowingtohostAARPTableServiceProvider'sNetworkServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVDHCPHeaderDHCPHeaderspoofingOp(1)Htype(1)Hlen(1)Hops(1)Xid(4)Secs(2)Flags(2)Ciaddr(4)Yiaddr(4)Siaddr(4)Giaddr(4)Chaddr(16)Sname(64)File(128)Options(Variable)ClientIdenrtifierRelayAgentOptionDSLAMAttackerxDSLL2RAL3RADHCPServerABDHCPRelease:MACB:SrcIP:BChaddr:A2Spoof'chaddr'fieldDHCPRelease:MACB:SrcIP:BClientId:A3Spoof'ClientIdentifier'fieldDHCPRelease:MACB:SrcIP:BOption82RemoteId:A4SpoofOption82fieldChangingInternalfieldswithinDHCPheaderDHCPRelease:MACB:SrcIP:BCiaddr:A1Spoof'ciaddr'field2009InfosysTechnologiesLimitedSANOGXIVSimilarlyPPPoESession-IDfieldidentifiesauniquesession.
SpoofingthiscanalsocauseservicedisruptionPPPoEHeaderPPPoEHeaderspoofingVERTYPECODESESSION_IDLENGTHPAYLOADChangingSESSION_IDfieldinPPPoEHeaderAttackerxDSLIPBIPAPPPoEIABRAS1PADT:SESSION_ID:ASessionDisconnectedServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVAnti-spoofingWhatisanti-spoofingMechanismtoidentifyspoofingandstoppingit.
Howanti-spoofingisdoneBydroppingthespoofedpacketsHowtoidentifythespoofedpacketsByverifyingIPAddressofthereceivedpacket.
ByverifyingMACaddressofthereceivedpacket.
ByverifyingthecombinationofIPandMACaddressforagiveninterfaceByverifyingtheIPaddress,MACaddressandothersessionbasedidentificationintheprotocolheader.
2009InfosysTechnologiesLimitedSANOGXIVDatarequiredforAnti-spoofingForeachuserconnectionListofValidIPaddressesassignedListofValidMACaddressesandifpossiblethecombinationofMACandIPaddresses,TimeforwhicheachIPaddressisvalid.
2009InfosysTechnologiesLimitedSANOGXIVWhyanti-spoofinginBroadbandAccessConcentrator(BAC)BACisattherightplace:Itknowsalltherequiredinformationtodoanti-spoofing.
Anti-spoofingbecomesdifficultandlesseffectiveifitisnotdoneasnearthesourceaspossible.
Itisnotonlyimportanttodropspoofedpackets,itisimportanttodropthemasearlyaspossible.
2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC-PPPoE1xDSLHomeHubBRASL3RAMetroRADIUS2PADIPADO34PADRPADSBACObtainSession-IDfromPADSIPMACSession-IDI/FAA1011BB1022PPPLCPPPPIPCPBACObtainIPinformationfromIPCP567PADTBACDeletethespoofingentry2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC-DHCPxDSLHomeHubBRASL3RAMetroDHCPIPMACLeaseI/FAA2001BB120212DHCPDISCOVERDHCPOFFER34DHCPREQUESTDHCPACKBACObtainIP/MAC/LeasetimefromDHCPACKMessage6DHCPRELEASEBACRemovetheentryfromtableLeaseEXPIREBACRemovetheentryfromtable2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC–802.
1x+DHCP1xDSLHomeHubBRASL3RAMetroDHCP2InitialEAPNegotiationsEAPAuthSuccess34DHCPMessageexchangeDHCPACKBACObtaintheMACaddressfromEAPAuthSuccessmessageIPMACLeaseI/FAA2001BB1202RADIUSBACObtainIP&LeasetimefromDHCPACKMessage2009InfosysTechnologiesLimitedSANOGXIVMACAntispoofingDSLAMAttackerAttackerxDSLMACI/FB2A1FloodtrafficwithbothMACAandMACBMACBNoImpactonAMACAMACBIPMACLeaseI/FBB1202Floodtrafficwith1000'sofSrcMACsinadditiontoMACBCompareAntispooftableanddiscardnonmatchingentriesNoMACtableExhaustion!
MACI/FB2MACTableAntiSpoofTableIPMACLeaseI/FAA2001BB1202CompareAntispooftableanddiscardnonmatchingentriesNospoofingofNeighbor'sMAC!
2009InfosysTechnologiesLimitedSANOGXIVIPAntispoofingAttackerxDSLIPBNoImpactonAIPASendtrafficwithIPAandMACB1IPMACLeaseI/FAA2001BB1202CompareIPagainstthei/finAntispooftableMetro2009InfosysTechnologiesLimitedSANOGXIVARPAntispoofingABCDARP:WhoisIPB1ARPReply:IamIPB:MACA2IPMACAABBARPTableABCDGratuitousARP:IamIPB:MACA1IPMACAABBARPTableIPMACLeaseI/FAA2001BB1202CompareIP/MACagainstthei/finAntispooftableIPMACLeaseI/FAA2001BB1202ServiceProviderN/wServiceProviderN/w2009InfosysTechnologiesLimitedSANOGXIVDHCPHeaderAntispoofingDSLAMAttackerxDSLL2RAL3RADHCPServerABDHCPRelease:MACB:SrcIP:BChaddr:A1AntiSpooffilterdiscardDHCPRelease:MACB:SrcIP:BOption82RemoteId:A3Option82fromuntrustedentity.
DiscardIPMACLeaseI/FAA2001BB1202InspectDHCPHeader&comparechaddr&ClientIDwithantispooftableAcceptDHCPwithoption82onlyifitiscomingfromtrustedentityDHCPRelease:MACB:SrcIP:BCiaddr:A2AntiSpooffilterdiscard2009InfosysTechnologiesLimitedSANOGXIVPPPoEHeaderAntispoofingAttackerxDSLIPBIPAPPPoEIABRAS1PADT:SESSION_ID:101IPMACSession-IDI/FAA1011BB1022SessionIDdoesnotmatchNoImpactonAMetro2009InfosysTechnologiesLimitedSANOGXIVLosingdatacollectedforanti-spoofingDatausedinAntispoofingcanbelostduetovariousreasonsPlannedrebootSoftwarecrashPowerfailureReplacementofsystemSoftwareupgrade2009InfosysTechnologiesLimitedSANOGXIVHowtorecoverlostdataStaticconfigurationRequiredDataisavailableintheconfiguration.
PPPoEForPPPoE,thekeep-alivetimersareconfiguredandthesessionisre-initiatediftherearenorepliestothekeep-alivemessagesDHCPDHCPdoesnothavekeepalivemechanisminplace.
DHCPhasa'leasetime'whichisusuallyinorderof'days'.
Howtorecoverfromthissituation2009InfosysTechnologiesLimitedSANOGXIVRecoveringLeaseinformationforDHCPStableStorage:NotveryusefulasnotmanyBACssupportstablestorage.
LimitederasecyclesisalsoabottleneckinthisapproachBroadcastARPs:NeedtowaitfordownstreamtraffictoarriveandinitiateARPrequests.
Willincreasethedelay.
Cannotgetthecompleteinformationinonerequest.
PronetospoofingattacksifamalicioususerrepliestotheARPrequest.
RedundantcontrollersBACcanhaveredundantcontrollersandupononecontrollercrash,theothercontrollercantakeoverwithpre-synchedleasedata.
Notsuitableforpowerfailurescenariosorforupgrades.
Havingredundantcontrollersalsoaddtohardwarecosts2009InfosysTechnologiesLimitedSANOGXIVRecoveringLeaseinformationforDHCPQuerythroughSNMP/LDAPCurrentlynostandardMIBsareavailableforDHCPleaseinformation.
BACstypicallydonotsupportSNMPclientinterfacesQueryleaseinformationfromDHCPserverSolvesmostoftheproblemsstatedabove2009InfosysTechnologiesLimitedSANOGXIVLeasequeryforDHCP(RFC4388)RFC4388introducedanewDHCPrequestLeasequerywhichaBACcanusetoqueryDHCPservertoobtainleaseinformation.
ThreetypesofqueriesaresupportedQuerybyIPaddressOnlyIPaddressispopulatedinthequerymessage.
QuerybyMACaddressOnlyMACaddressispopulatedinthequerymessage.
Ifmorethanoneleaseisavailable,thencorrespondingIPaddressesarereturnedinassociated-ipoption.
BACthengetsadditionaldatabygeneratingquerybyIPaddress.
QuerybyClientidentifierOnlyclientidentifieroptionispopulatedinthequerymessage.
Ifmorethanoneleaseisavailable,thencorrespondingIPaddressesarereturnedinassociated-ipoption.
BACthengetstheadditionaldatabyqueryingbyIPaddress.
2009InfosysTechnologiesLimitedSANOGXIVLeasequeryforDHCP(RFC4388)Threetypesofreplymessagetypesareintroduced:DHCPLEASEACTIVEWhenDHCPserverknowsaboutthequeryidentifier.
DHCPLEASEUNKNOWN:WhenDHCPserverdoesnotknowaboutthequeryidentifier.
AnAccessConcentratorcachethisinformationsothatthiscanbeusedtoavoidgeneratingLeaseQueryforthequeryidentifier.
ThisisknownasNegativeCaching.
DHCPLEASEUNASSIGNED:WhenDHCPserverdoesmanagethequeryidentifierbutnoleaseisyetassigned.
NegativeCachingisdoneforthisresponseaswell.
2009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven34DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1MACIPLeaseI/fM1192.
168.
1.
2T1I1AntiSpoofTable123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven35DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerCRASHMACIPLeaseI/fAntiSpoofTable123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven36DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServer1DataTrafficfrom192.
168.
1.
22LeaseQuerybyIPAddress3LeaseActiveM1,T1,I1MACIPLeaseI/fM1192.
168.
1.
2T1I1AntiSpoofTable4DataTrafficfrom192.
168.
1.
25123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching37xDSLHomeHubServiceProviderNetworkDHCPServerCRASH123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching381DataTrafficfrom192.
168.
1.
102LeaseQuerybyIPAddressNegativeCachingxDSLHomeHubServiceProviderNetworkDHCPServer123MACIPThresholdI/fM1192.
168.
1.
10T1I13LeaseUNKNOWN182.
168.
1.
10,M14I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching392DataTrafficfrom192.
168.
1.
103LeaseQuerybyIPAddressNegativeCachingxDSLHomeHubServiceProviderNetworkDHCPServer123MACIPThresholdI/fM1192.
168.
1.
10T1I14LeaseUNKNOWN182.
168.
1.
10,M1Thresholdexpired1I12009InfosysTechnologiesLimitedSANOGXIVIssueswithRFC4388basedleasequeryExistingLeasequerymechanismisdatadriven:LeasequeryisinitiatedonlywhenAccessConcentratorsreceivesdataExistingmethodsuggeststheuseofnegativecaching.
NegativeCachingconsumeslotofresourcesunderspoofattacks.
Resultsinincreasedoutagetimefortheclients.
2009InfosysTechnologiesLimitedSANOGXIVIssueswithRFC4388basedleasequery(contd.
.
)Gettingconsolidatedleaseinformationperconnectionisnotpossible:Existingmechanismdoesn'thaveanymethodstogetconsolidatedleaseinformationforalltheclientsbelongingtoaconnection/circuitMultipleclientscanresideforagivenconnection/circuit.
IfAccessconcentratorhasleaseinformationofalltheclientsforagivenconnection/circuit,anti-spoofingcanbedoneindataplane(fastpath)2009InfosysTechnologiesLimitedSANOGXIVQuerybyremote-idRemote-IDsuboptionidentifyiesaconnection/circuituniquely.
ThisisgloballyuniqueidentifierRemote-IDcanbetrustedastheyarecreatedbyRelayAgent.
AccessConcentratorneednotwaitforthetraffictoarriveandcangenerateLeaseQueryassoonasitcomesupafterareboot.
DHCPServercanprovideconsolidatedLeaseInformationforaspecificconnection/circuit.
Oncealltheleaseinformationforagivenconnection/circuitisobtained,anti-spoofingcanbedoneindataplane(fastpath).
NoneedforNegativeCaching.
2009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId43xDSLHomeHubServiceProviderNetworkDHCPServer123M1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1M3192.
168.
1.
10T3I1MACIPLeaseI/fAntiSpoofTableI12009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId44xDSLHomeHubServiceProviderNetworkDHCPServerCRASH123MACIPLeaseI/fAntiSpoofTableI12009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId451LeaseQuerybyRemoteIdforI12LeaseActiveofallthreeleases*3DataTrafficfrom192.
168.
1.
8xDSLHomeHubServiceProviderNetworkDHCPServer123M1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1M3192.
168.
1.
10T3I1MACIPLeaseI/fAntiSpoofTable4DataTrafficfrom192.
168.
1.
8BACdoesnotneedtowaitforthetraffictoinitiateLQLeasequerybyremote-idresultsinobtainingcompleteinformationonagiveninterface.
NoneedofinitiatingsubsequentqueriesI1*Leaseactiveforoneleaseisreturnedfollowedbyassociated-IPoption.
ThisresultsinsubsequentquerybyIPforremainingleases2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:ServeridentifiesaLeasequerybyremote-idwhentheleasequerymessagehas:Chaddr,siaddr,Ciaddr,htype,hlenandchaddriszeroandClientidentifieroptionisnotpresentandOption82withonlyRemote-Idsub-optionispresent.
SendsaLEASEACTIVEpopulatingtheciaddrwiththeIPaddressthatwasmostrecentlyaccessedbytheclient.
AllotherIPaddressesarereturnedinAssociated-IPoption.
RelayagentthensendsaLeasequerywith"QuerybyIPAddress"foralltheadditionalIPaddressesreturnedinAssociated-ipoption.
2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:ServermayreturnaLEASEUNASSIGNEDifitknowsitmanagestheleasefortheconnectionidentifiedbyRemote-Idsub-optionbutnoleaseisassignedyet.
ServermayreturnLEASEUNKNOWNifitdoesnotknowthecorrespondingRemote-idsub-option.
2009InfosysTechnologiesLimitedSANOGXIVWhyBulkLeasequeryTraditionalleasequery(Both4388)andleasequerybyremote-idworksontheprincipleofretrievingoneleaseatatimeWhilequerybyremote-idsolvesalltheproblemsassociatedwithRFC4388basedleasequerymechanism,itstillinvolvesgeneratinghugenumberofleasequeriestogetallthepossibledataBulkleasequeryworksontheprincipleofestablishingTCPconnectionbetweenRAandServerandretrievinginformationinbulk2009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery49DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerMACIPAddressLeaseTimeInterfaceM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I2M3192.
168.
1.
3T2I3I1I2I32009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery50DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerCRASHI1I2I3MACIPLeaseI/f2009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery51DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerMACIPAddressLeaseTimeInterfaceM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I2M3192.
168.
1.
3T2I33DataTrafficfrom192.
168.
1.
81BulkLeaseQueryinaTCPSession2LeaseActiveofallleases4DataTrafficfrom192.
168.
1.
8LeaseinformationofallinterfacesobtainedininonequeryI1I2I32009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServer1TCPSession2BulkLeaseQuerywithXID23LEASEQUERYACTIVEforXID24LEASEQUERYACTIVEforXID25LEASEQUERYACTIVEforXID26LEASEQUERYDONEforXID27TCPsessionclose2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:AQuerier(TypicallyaRelayAgent)establishesaTCPconnectionwiththeserveronport67.
Twonewquerytypesareadded"QuerybyRelay-ID"whererelay-idisauniqueRelayagentIdentifier.
AllleasesallocatedthroughaspecificRelayAgent.
"QueryforallconfiguredIPs"whereallIPaddressheldbyDHCPServerirrespectiveofstateisreturned.
Inthiscase,unassignedIPaddressesarereturnedwithUNASSIGNEDstate.
Newfiltersareadded:StartandEndtimefiltercanbepassedtoretrieveleasesforwhichstatehaschangedwithinthespecifiedtime.
Otherquerytypes(QuerybyIPAddress,MACaddress,Client-IDandremote-id)arealsosupported.
2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:UponreceivingaBULKLEASEQUERY,DHCPservergeneratesastreamofLEASEACTIVEforeachleasethatfulfilsthequery.
EndofleaseforagivenqueryisindicatedbytheLEASEQUERYDONEmessage.
MultipleBulkLeasequerycanbeinitiatedoverasingleTCPconnection.
Transactionid(XID)isusedtodistinguishbetweentherepliesformultiplequeries.
2009InfosysTechnologiesLimitedSANOGXIVStandardizationandImplementationeffortsStandardizationefforts:Querybyremote-idandBulkLeaseQuerydraftisbeingstandardizedinDHCworkinggroupofIETF.
Implementationefforts:WehavecreatedaProof-Of-Conceptimplementationof'QuerybyRemote-Id'and'BulkLeaseQuery'byenhancingISCDHCPserver.
2009InfosysTechnologiesLimitedSANOGXIVReferences:S.
Bellovin,"SecurityproblemsintheTCP/IPprotocolsuite,"SIGCOMMComputerCommunicationReview,vol.
19,no.
2,pp.
32–48,1989.
R.
BeverlyandS.
Bauer,"Thespooferproject:inferringtheextentofsourceaddressfilteringontheinternet,"inSRUTI'05:Proc.
oftheStepstoReducingUnwantedTrafficontheInternet,2005.
IETFStandards:RFC2131,DynamicHostConfigurationProtocolLayer2RelayAgenthttp://www.
ietf.
org/id/draft-ietf-dhc-l2ra-04.
txthttp://www.
ietf.
org/id/draft-ietf-dhc-l2ra-extensions-01.
txtQuerybyremote-idhttp://www.
ietf.
org/id/draft-ietf-dhc-leasequery-by-remote-id-02.
txtBulkleasequeryhttp://www.
ietf.
org/id/draft-ietf-dhc-dhcpv4-bulk-leasequery-00.
txtTR-101fromBroadbandForumhttp://www.
broadband-forum.
org/technical/download/TR-101.
pdf2009InfosysTechnologiesLimitedSANOGXIV2009InfosysTechnologiesLimitedSANOGXIVThankYou

vdsina:俄罗斯VPS(datapro),6卢布/天,1G内存/1核(AMD EPYC 7742)/5gNVMe/10T流量

今天获得消息,vdsina上了AMD EPYC系列的VDS,性价比比较高,站长弄了一个,盲猜CPU是AMD EPYC 7B12(经过咨询,详细CPU型号是“EPYC 7742”)。vdsina,俄罗斯公司,2014年开始运作至今,在售卖多类型VPS和独立服务器,可供选择的有俄罗斯莫斯科datapro和荷兰Serverius数据中心。付款比较麻烦:信用卡、webmoney、比特币,不支持PayPal...

NameCheap黑色星期五和网络礼拜一

如果我们较早关注NameCheap商家的朋友应该记得前几年商家黑色星期五和网络星期一的时候大促采用的闪购活动,每一个小时轮番变化一次促销活动而且限量的。那时候会导致拥挤官网打不开迟缓的问题。从去年开始,包括今年,NameCheap商家比较直接的告诉你黑色星期五和网络星期一为期6天的活动。没有给你限量的活动,只有限时六天,这个是到11月29日。如果我们有需要新注册、转入域名的可以参加,优惠力度还是比...

Hostinger 限时外贸美国主机活动 低至月12元且赠送1个COM域名

Hostinger 商家我们可能一些新用户不是太熟悉,因为我们很多新人用户都可能较多的直接从云服务器、独立服务器起步的。而Hostinger商家已经有将近十年的历史的商家,曾经主做低价虚拟主机,也是比较有知名度的,那时候也有接触过,不过一直没有过多的使用。这不这么多年过去,Hostinger商家一直比较稳妥的在运营,最近看到这个商家在改版UI后且产品上也在活动策划比较多。目前Hostinger在进...

option82为你推荐
汇通物流百世物流和百世汇通哪个快?西部妈妈网九芽妈妈网加盟费多少同ip网站查询怎样查询一个ip绑了多少域名www.983mm.com哪有mm图片?你懂得比肩工场大运比肩主事,运行长生地是什么意思?地陷裂口地陷前期会有什么征兆吗?杰景新特我准备在网上买杰普特711RBES长笛,10700元,这价格合理吗?还有,这是纯银的吗,是国内组装的吗?rawtoolsTF卡被写保护了怎么办?同ip域名不同域名解析到同一个IP是否有影响www.522av.com在白虎网站bhwz.com看电影要安装什么播放器?
哈尔滨服务器租用 vps教程 国外vps租用 hawkhost优惠码 vpsio ssh帐号 腾讯云分析 世界测速 百度云1t t云 in域名 海外空间 免费asp空间 德讯 iki 免费个人主页 xuni 购买空间 江苏徐州移动 中国电信宽带测速 更多