Changeoption82
option82 时间:2021-04-04 阅读:(
)
2009InfosysTechnologiesLimitedSANOGXIV2009InfosysTechnologiesLimitedSANOGXIVTacklingSpoofingAttacksinBroadbandAccessNetworksBharatJoshi(bharat_joshi@infosys.
com)PavanKurapati(pavan_kurapati@infosys.
com)RamakrishnaRaoDTV(ramakrishnadtv@infosys.
com)2009InfosysTechnologiesLimitedSANOGXIVAgendaSpoofing–What,WhyandHowTypesofuserconnectionsinBroadbandAccessConcentratorsTypesofspoofingHowtocollectdatatodoAnti-spoofinginAccessNetworkAnti-spoofingHowtorecoveranti-spoofingdataafterBACcrash/reboot2009InfosysTechnologiesLimitedSANOGXIVWhatisSpoofiingSpoofingisaprocesswherebyoneentitymasqueradesasanotherentityWhyisspoofingdoneSpoofingAbyBisdoneforvariouspurposesBseekstheprivilegesofABintendstohideitstracksAsanattackonAHowisspoofingdoneWeshallseeincomingslides2009InfosysTechnologiesLimitedSANOGXIVTheultimategoalofspoofingUnauthorizedServiceGetserviceonsomeoneelse'sexpenseLossofServiceonTargetMakesurethatthetargetdoesnotgetanyserviceDifficulttotracetheattackerMakesurethatpeoplecannotfindwhoattackedthem.
UnnecessarypacketscloggingthenetworkMakesurethatnobodygetsagoodservice.
SecondaryvictimPrimarytargetrespondstospoofpacketandoverwhelmthesourcewhichbecomessecondaryvictim.
2009InfosysTechnologiesLimitedSANOGXIVTypesofuserconnectionsforanIPbasedDSLAMBridgedIPRoutingRFC2684basedbridgedencapsulationbetweenEndUserandDSLAMDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fDynamicIPallocationusingDHCPPPPoE/APPPterminationinDSLAMIPallocationfromlocalpoolDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fIPoARFC2684basedroutedencapsulationbetweenEndUserandDSLAMDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fDynamicIPallocationusingDHCPL3DSLAMxDSLHomeHubxDSLHomeHubMPLSCloudPEPRouterPRouterBRASL3n/wDataCenterL3DSLAMInternetservices2009InfosysTechnologiesLimitedSANOGXIV6DSLAML3AxDSLHomeHubL3n/wDHCP2UnicastDISCOVER+Option82populatedwithRemote-ID/Circuit-ID1BroadcastDHCPDISCOVERUnicastDHCPOFFERwithoption82echoed3SendDHCPOFFERtothehostafterremovingoption8246UnicastREQUEST+Option82populatedwithRemote-ID/Circuit-ID5BroadcastDHCPREQUESTUnicastDHCPACKtotheclientwithoption827SendDHCPACKtothehostafterremovingoption828AddressallocationmechanismsforIPDSLAM–DHCP2009InfosysTechnologiesLimitedSANOGXIVTypesofuserconnectionsforaLayer2DSLAM1:1VLANsMapeveryuserconnectiontooneunique802.
1qbasedVLANNoneedofanyMAClearningofindividualhostsDownstreamtrafficmappingdonebasedonVLANsQinQorStackedVLANsAnouterServiceVLANidentifyingaspecificserviceisaddedDownstreammappingdonebasedoncombinationofCVLANandSVLANN:1TransparentBridgedVLANsMultipleusersmappedtoacommonVLANDownstreammappingdonebasedonVLANandDstMACcombinationMAClearningisrequiredforoperationL2DSLAMxDSLHomeHubxDSLHomeHubMPLSCloudPEPRouterPRouterBRASAccessAggregationDataCenterL2DSLAMInternetservices2009InfosysTechnologiesLimitedSANOGXIV8DSLAML2RAxDSLHomeHubBRASL3RAMetroDHCP2BroadcastDISCOVER+Option82populatedwithRemote-ID/Circuit-ID1BroadcastDHCPDISCOVER3UnicastDISCOVERwith'giaddr'populatedUnicastDHCPOFFERwithoption82echoed45BroadcastDHCPOFFERwithoption82andwithout'giaddr'SendDHCPOFFERtothehostafterremovingoption8268BroadcastREQUEST+Option82populatedwithRemote-ID/Circuit-ID7BroadcastDHCPREQUEST9UnicastREQUESTwith'giaddr'populatedUnicastDHCPACKtotheclientwithoption8210SendDHCPACKtothehostafterremovingoption8211AddressallocationmechanismsforL2DSLAM–DHCP2009InfosysTechnologiesLimitedSANOGXIV9DSLAML2RAxDSLHomeHubBRASL3RAMetroDHCPRADIUSPortEnabled1EAPOLStart2IdentityRequest3IdentityResponse4IdentityDetails5EAPMD5Challenge6MD5ChallengeResponse7AuthSuccess8AuthSuccess9DHCPAuthentication&AddressallocationmechanismsforL2DSLAM–DHCP+802.
1x2009InfosysTechnologiesLimitedSANOGXIV10DSLAMxDSLHomeHubBRASMetroRADIUS2PADI+IntermediateAgentpopulatedwithRemote-ID/Circuit-ID1PADIPADO+IntermediateAgentechoed35PADR6PADR+IntermediateAgentpopulatedwithRemote-ID/Circuit-IDPADS+IntermediateAgentechoed79PPPNegotiationsAuthentication&AddressallocationmechanismsforL2DSLAM-PPPoEPADOafterremovingagentinformationoption4PADSafterremovingagentinformationoption82009InfosysTechnologiesLimitedSANOGXIVTypeofSpoofingMACSpoofingIPSpoofingARPSpoofingControlprotocolinternalheaderspoofingPPPoEsession-idspoofingDHCPchaddr,ciaddr,relay-agent-informationoptionspoofing2009InfosysTechnologiesLimitedSANOGXIV12DSLAMAttackerChangeSrcMACaddressandfloodtrafficSimulates1000sofMACaddressatfasterratexDSLMACTablemaximumlimitreachedLegitimatetrafficdroppedduetoMACtableexhaustionChangingSourceMACaddresstoanillegitimateaddressAttackerxDSLMACI/FB2A2FloodtrafficwithbothMACAandMACBMACBLegitimatetrafficblockedMACAMACspoofing2009InfosysTechnologiesLimitedSANOGXIVIPspoofingChangingSourceIPaddresstoanillegitimateaddressAttackerxDSLIPBDoSattackonIPAIPASendtrafficwithIPAandMACBRepliesfloodedtoIPA12PingofDeathServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVARPspoofingRespond/sendARPResponsewithillegitimateIPaddressABCDARP:WhoisIPB1ARPReply:IamIPB:MACA2IPMACAABATrafficflowingtohostAARPTableABCDGratuitousARP:IamIPB:MACA1IPMACAABATrafficflowingtohostAARPTableServiceProvider'sNetworkServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVDHCPHeaderDHCPHeaderspoofingOp(1)Htype(1)Hlen(1)Hops(1)Xid(4)Secs(2)Flags(2)Ciaddr(4)Yiaddr(4)Siaddr(4)Giaddr(4)Chaddr(16)Sname(64)File(128)Options(Variable)ClientIdenrtifierRelayAgentOptionDSLAMAttackerxDSLL2RAL3RADHCPServerABDHCPRelease:MACB:SrcIP:BChaddr:A2Spoof'chaddr'fieldDHCPRelease:MACB:SrcIP:BClientId:A3Spoof'ClientIdentifier'fieldDHCPRelease:MACB:SrcIP:BOption82RemoteId:A4SpoofOption82fieldChangingInternalfieldswithinDHCPheaderDHCPRelease:MACB:SrcIP:BCiaddr:A1Spoof'ciaddr'field2009InfosysTechnologiesLimitedSANOGXIVSimilarlyPPPoESession-IDfieldidentifiesauniquesession.
SpoofingthiscanalsocauseservicedisruptionPPPoEHeaderPPPoEHeaderspoofingVERTYPECODESESSION_IDLENGTHPAYLOADChangingSESSION_IDfieldinPPPoEHeaderAttackerxDSLIPBIPAPPPoEIABRAS1PADT:SESSION_ID:ASessionDisconnectedServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVAnti-spoofingWhatisanti-spoofingMechanismtoidentifyspoofingandstoppingit.
Howanti-spoofingisdoneBydroppingthespoofedpacketsHowtoidentifythespoofedpacketsByverifyingIPAddressofthereceivedpacket.
ByverifyingMACaddressofthereceivedpacket.
ByverifyingthecombinationofIPandMACaddressforagiveninterfaceByverifyingtheIPaddress,MACaddressandothersessionbasedidentificationintheprotocolheader.
2009InfosysTechnologiesLimitedSANOGXIVDatarequiredforAnti-spoofingForeachuserconnectionListofValidIPaddressesassignedListofValidMACaddressesandifpossiblethecombinationofMACandIPaddresses,TimeforwhicheachIPaddressisvalid.
2009InfosysTechnologiesLimitedSANOGXIVWhyanti-spoofinginBroadbandAccessConcentrator(BAC)BACisattherightplace:Itknowsalltherequiredinformationtodoanti-spoofing.
Anti-spoofingbecomesdifficultandlesseffectiveifitisnotdoneasnearthesourceaspossible.
Itisnotonlyimportanttodropspoofedpackets,itisimportanttodropthemasearlyaspossible.
2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC-PPPoE1xDSLHomeHubBRASL3RAMetroRADIUS2PADIPADO34PADRPADSBACObtainSession-IDfromPADSIPMACSession-IDI/FAA1011BB1022PPPLCPPPPIPCPBACObtainIPinformationfromIPCP567PADTBACDeletethespoofingentry2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC-DHCPxDSLHomeHubBRASL3RAMetroDHCPIPMACLeaseI/FAA2001BB120212DHCPDISCOVERDHCPOFFER34DHCPREQUESTDHCPACKBACObtainIP/MAC/LeasetimefromDHCPACKMessage6DHCPRELEASEBACRemovetheentryfromtableLeaseEXPIREBACRemovetheentryfromtable2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC–802.
1x+DHCP1xDSLHomeHubBRASL3RAMetroDHCP2InitialEAPNegotiationsEAPAuthSuccess34DHCPMessageexchangeDHCPACKBACObtaintheMACaddressfromEAPAuthSuccessmessageIPMACLeaseI/FAA2001BB1202RADIUSBACObtainIP&LeasetimefromDHCPACKMessage2009InfosysTechnologiesLimitedSANOGXIVMACAntispoofingDSLAMAttackerAttackerxDSLMACI/FB2A1FloodtrafficwithbothMACAandMACBMACBNoImpactonAMACAMACBIPMACLeaseI/FBB1202Floodtrafficwith1000'sofSrcMACsinadditiontoMACBCompareAntispooftableanddiscardnonmatchingentriesNoMACtableExhaustion!
MACI/FB2MACTableAntiSpoofTableIPMACLeaseI/FAA2001BB1202CompareAntispooftableanddiscardnonmatchingentriesNospoofingofNeighbor'sMAC!
2009InfosysTechnologiesLimitedSANOGXIVIPAntispoofingAttackerxDSLIPBNoImpactonAIPASendtrafficwithIPAandMACB1IPMACLeaseI/FAA2001BB1202CompareIPagainstthei/finAntispooftableMetro2009InfosysTechnologiesLimitedSANOGXIVARPAntispoofingABCDARP:WhoisIPB1ARPReply:IamIPB:MACA2IPMACAABBARPTableABCDGratuitousARP:IamIPB:MACA1IPMACAABBARPTableIPMACLeaseI/FAA2001BB1202CompareIP/MACagainstthei/finAntispooftableIPMACLeaseI/FAA2001BB1202ServiceProviderN/wServiceProviderN/w2009InfosysTechnologiesLimitedSANOGXIVDHCPHeaderAntispoofingDSLAMAttackerxDSLL2RAL3RADHCPServerABDHCPRelease:MACB:SrcIP:BChaddr:A1AntiSpooffilterdiscardDHCPRelease:MACB:SrcIP:BOption82RemoteId:A3Option82fromuntrustedentity.
DiscardIPMACLeaseI/FAA2001BB1202InspectDHCPHeader&comparechaddr&ClientIDwithantispooftableAcceptDHCPwithoption82onlyifitiscomingfromtrustedentityDHCPRelease:MACB:SrcIP:BCiaddr:A2AntiSpooffilterdiscard2009InfosysTechnologiesLimitedSANOGXIVPPPoEHeaderAntispoofingAttackerxDSLIPBIPAPPPoEIABRAS1PADT:SESSION_ID:101IPMACSession-IDI/FAA1011BB1022SessionIDdoesnotmatchNoImpactonAMetro2009InfosysTechnologiesLimitedSANOGXIVLosingdatacollectedforanti-spoofingDatausedinAntispoofingcanbelostduetovariousreasonsPlannedrebootSoftwarecrashPowerfailureReplacementofsystemSoftwareupgrade2009InfosysTechnologiesLimitedSANOGXIVHowtorecoverlostdataStaticconfigurationRequiredDataisavailableintheconfiguration.
PPPoEForPPPoE,thekeep-alivetimersareconfiguredandthesessionisre-initiatediftherearenorepliestothekeep-alivemessagesDHCPDHCPdoesnothavekeepalivemechanisminplace.
DHCPhasa'leasetime'whichisusuallyinorderof'days'.
Howtorecoverfromthissituation2009InfosysTechnologiesLimitedSANOGXIVRecoveringLeaseinformationforDHCPStableStorage:NotveryusefulasnotmanyBACssupportstablestorage.
LimitederasecyclesisalsoabottleneckinthisapproachBroadcastARPs:NeedtowaitfordownstreamtraffictoarriveandinitiateARPrequests.
Willincreasethedelay.
Cannotgetthecompleteinformationinonerequest.
PronetospoofingattacksifamalicioususerrepliestotheARPrequest.
RedundantcontrollersBACcanhaveredundantcontrollersandupononecontrollercrash,theothercontrollercantakeoverwithpre-synchedleasedata.
Notsuitableforpowerfailurescenariosorforupgrades.
Havingredundantcontrollersalsoaddtohardwarecosts2009InfosysTechnologiesLimitedSANOGXIVRecoveringLeaseinformationforDHCPQuerythroughSNMP/LDAPCurrentlynostandardMIBsareavailableforDHCPleaseinformation.
BACstypicallydonotsupportSNMPclientinterfacesQueryleaseinformationfromDHCPserverSolvesmostoftheproblemsstatedabove2009InfosysTechnologiesLimitedSANOGXIVLeasequeryforDHCP(RFC4388)RFC4388introducedanewDHCPrequestLeasequerywhichaBACcanusetoqueryDHCPservertoobtainleaseinformation.
ThreetypesofqueriesaresupportedQuerybyIPaddressOnlyIPaddressispopulatedinthequerymessage.
QuerybyMACaddressOnlyMACaddressispopulatedinthequerymessage.
Ifmorethanoneleaseisavailable,thencorrespondingIPaddressesarereturnedinassociated-ipoption.
BACthengetsadditionaldatabygeneratingquerybyIPaddress.
QuerybyClientidentifierOnlyclientidentifieroptionispopulatedinthequerymessage.
Ifmorethanoneleaseisavailable,thencorrespondingIPaddressesarereturnedinassociated-ipoption.
BACthengetstheadditionaldatabyqueryingbyIPaddress.
2009InfosysTechnologiesLimitedSANOGXIVLeasequeryforDHCP(RFC4388)Threetypesofreplymessagetypesareintroduced:DHCPLEASEACTIVEWhenDHCPserverknowsaboutthequeryidentifier.
DHCPLEASEUNKNOWN:WhenDHCPserverdoesnotknowaboutthequeryidentifier.
AnAccessConcentratorcachethisinformationsothatthiscanbeusedtoavoidgeneratingLeaseQueryforthequeryidentifier.
ThisisknownasNegativeCaching.
DHCPLEASEUNASSIGNED:WhenDHCPserverdoesmanagethequeryidentifierbutnoleaseisyetassigned.
NegativeCachingisdoneforthisresponseaswell.
2009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven34DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1MACIPLeaseI/fM1192.
168.
1.
2T1I1AntiSpoofTable123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven35DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerCRASHMACIPLeaseI/fAntiSpoofTable123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven36DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServer1DataTrafficfrom192.
168.
1.
22LeaseQuerybyIPAddress3LeaseActiveM1,T1,I1MACIPLeaseI/fM1192.
168.
1.
2T1I1AntiSpoofTable4DataTrafficfrom192.
168.
1.
25123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching37xDSLHomeHubServiceProviderNetworkDHCPServerCRASH123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching381DataTrafficfrom192.
168.
1.
102LeaseQuerybyIPAddressNegativeCachingxDSLHomeHubServiceProviderNetworkDHCPServer123MACIPThresholdI/fM1192.
168.
1.
10T1I13LeaseUNKNOWN182.
168.
1.
10,M14I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching392DataTrafficfrom192.
168.
1.
103LeaseQuerybyIPAddressNegativeCachingxDSLHomeHubServiceProviderNetworkDHCPServer123MACIPThresholdI/fM1192.
168.
1.
10T1I14LeaseUNKNOWN182.
168.
1.
10,M1Thresholdexpired1I12009InfosysTechnologiesLimitedSANOGXIVIssueswithRFC4388basedleasequeryExistingLeasequerymechanismisdatadriven:LeasequeryisinitiatedonlywhenAccessConcentratorsreceivesdataExistingmethodsuggeststheuseofnegativecaching.
NegativeCachingconsumeslotofresourcesunderspoofattacks.
Resultsinincreasedoutagetimefortheclients.
2009InfosysTechnologiesLimitedSANOGXIVIssueswithRFC4388basedleasequery(contd.
.
)Gettingconsolidatedleaseinformationperconnectionisnotpossible:Existingmechanismdoesn'thaveanymethodstogetconsolidatedleaseinformationforalltheclientsbelongingtoaconnection/circuitMultipleclientscanresideforagivenconnection/circuit.
IfAccessconcentratorhasleaseinformationofalltheclientsforagivenconnection/circuit,anti-spoofingcanbedoneindataplane(fastpath)2009InfosysTechnologiesLimitedSANOGXIVQuerybyremote-idRemote-IDsuboptionidentifyiesaconnection/circuituniquely.
ThisisgloballyuniqueidentifierRemote-IDcanbetrustedastheyarecreatedbyRelayAgent.
AccessConcentratorneednotwaitforthetraffictoarriveandcangenerateLeaseQueryassoonasitcomesupafterareboot.
DHCPServercanprovideconsolidatedLeaseInformationforaspecificconnection/circuit.
Oncealltheleaseinformationforagivenconnection/circuitisobtained,anti-spoofingcanbedoneindataplane(fastpath).
NoneedforNegativeCaching.
2009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId43xDSLHomeHubServiceProviderNetworkDHCPServer123M1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1M3192.
168.
1.
10T3I1MACIPLeaseI/fAntiSpoofTableI12009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId44xDSLHomeHubServiceProviderNetworkDHCPServerCRASH123MACIPLeaseI/fAntiSpoofTableI12009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId451LeaseQuerybyRemoteIdforI12LeaseActiveofallthreeleases*3DataTrafficfrom192.
168.
1.
8xDSLHomeHubServiceProviderNetworkDHCPServer123M1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1M3192.
168.
1.
10T3I1MACIPLeaseI/fAntiSpoofTable4DataTrafficfrom192.
168.
1.
8BACdoesnotneedtowaitforthetraffictoinitiateLQLeasequerybyremote-idresultsinobtainingcompleteinformationonagiveninterface.
NoneedofinitiatingsubsequentqueriesI1*Leaseactiveforoneleaseisreturnedfollowedbyassociated-IPoption.
ThisresultsinsubsequentquerybyIPforremainingleases2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:ServeridentifiesaLeasequerybyremote-idwhentheleasequerymessagehas:Chaddr,siaddr,Ciaddr,htype,hlenandchaddriszeroandClientidentifieroptionisnotpresentandOption82withonlyRemote-Idsub-optionispresent.
SendsaLEASEACTIVEpopulatingtheciaddrwiththeIPaddressthatwasmostrecentlyaccessedbytheclient.
AllotherIPaddressesarereturnedinAssociated-IPoption.
RelayagentthensendsaLeasequerywith"QuerybyIPAddress"foralltheadditionalIPaddressesreturnedinAssociated-ipoption.
2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:ServermayreturnaLEASEUNASSIGNEDifitknowsitmanagestheleasefortheconnectionidentifiedbyRemote-Idsub-optionbutnoleaseisassignedyet.
ServermayreturnLEASEUNKNOWNifitdoesnotknowthecorrespondingRemote-idsub-option.
2009InfosysTechnologiesLimitedSANOGXIVWhyBulkLeasequeryTraditionalleasequery(Both4388)andleasequerybyremote-idworksontheprincipleofretrievingoneleaseatatimeWhilequerybyremote-idsolvesalltheproblemsassociatedwithRFC4388basedleasequerymechanism,itstillinvolvesgeneratinghugenumberofleasequeriestogetallthepossibledataBulkleasequeryworksontheprincipleofestablishingTCPconnectionbetweenRAandServerandretrievinginformationinbulk2009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery49DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerMACIPAddressLeaseTimeInterfaceM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I2M3192.
168.
1.
3T2I3I1I2I32009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery50DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerCRASHI1I2I3MACIPLeaseI/f2009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery51DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerMACIPAddressLeaseTimeInterfaceM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I2M3192.
168.
1.
3T2I33DataTrafficfrom192.
168.
1.
81BulkLeaseQueryinaTCPSession2LeaseActiveofallleases4DataTrafficfrom192.
168.
1.
8LeaseinformationofallinterfacesobtainedininonequeryI1I2I32009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServer1TCPSession2BulkLeaseQuerywithXID23LEASEQUERYACTIVEforXID24LEASEQUERYACTIVEforXID25LEASEQUERYACTIVEforXID26LEASEQUERYDONEforXID27TCPsessionclose2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:AQuerier(TypicallyaRelayAgent)establishesaTCPconnectionwiththeserveronport67.
Twonewquerytypesareadded"QuerybyRelay-ID"whererelay-idisauniqueRelayagentIdentifier.
AllleasesallocatedthroughaspecificRelayAgent.
"QueryforallconfiguredIPs"whereallIPaddressheldbyDHCPServerirrespectiveofstateisreturned.
Inthiscase,unassignedIPaddressesarereturnedwithUNASSIGNEDstate.
Newfiltersareadded:StartandEndtimefiltercanbepassedtoretrieveleasesforwhichstatehaschangedwithinthespecifiedtime.
Otherquerytypes(QuerybyIPAddress,MACaddress,Client-IDandremote-id)arealsosupported.
2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:UponreceivingaBULKLEASEQUERY,DHCPservergeneratesastreamofLEASEACTIVEforeachleasethatfulfilsthequery.
EndofleaseforagivenqueryisindicatedbytheLEASEQUERYDONEmessage.
MultipleBulkLeasequerycanbeinitiatedoverasingleTCPconnection.
Transactionid(XID)isusedtodistinguishbetweentherepliesformultiplequeries.
2009InfosysTechnologiesLimitedSANOGXIVStandardizationandImplementationeffortsStandardizationefforts:Querybyremote-idandBulkLeaseQuerydraftisbeingstandardizedinDHCworkinggroupofIETF.
Implementationefforts:WehavecreatedaProof-Of-Conceptimplementationof'QuerybyRemote-Id'and'BulkLeaseQuery'byenhancingISCDHCPserver.
2009InfosysTechnologiesLimitedSANOGXIVReferences:S.
Bellovin,"SecurityproblemsintheTCP/IPprotocolsuite,"SIGCOMMComputerCommunicationReview,vol.
19,no.
2,pp.
32–48,1989.
R.
BeverlyandS.
Bauer,"Thespooferproject:inferringtheextentofsourceaddressfilteringontheinternet,"inSRUTI'05:Proc.
oftheStepstoReducingUnwantedTrafficontheInternet,2005.
IETFStandards:RFC2131,DynamicHostConfigurationProtocolLayer2RelayAgenthttp://www.
ietf.
org/id/draft-ietf-dhc-l2ra-04.
txthttp://www.
ietf.
org/id/draft-ietf-dhc-l2ra-extensions-01.
txtQuerybyremote-idhttp://www.
ietf.
org/id/draft-ietf-dhc-leasequery-by-remote-id-02.
txtBulkleasequeryhttp://www.
ietf.
org/id/draft-ietf-dhc-dhcpv4-bulk-leasequery-00.
txtTR-101fromBroadbandForumhttp://www.
broadband-forum.
org/technical/download/TR-101.
pdf2009InfosysTechnologiesLimitedSANOGXIV2009InfosysTechnologiesLimitedSANOGXIVThankYou
GreencloudVPS此次在四个机房都上线10Gbps大带宽VPS,并且全部采用AMD处理器,其中美国芝加哥机房采用Ryzen 3950x处理器,新加坡、荷兰阿姆斯特丹、美国杰克逊维尔机房采用Ryzen 3960x处理器,全部都是RAID-1 NVMe硬盘、DDR4 2666Mhz内存,GreenCloudVPS本次促销的便宜VPS最低仅需20美元/年,支持支付宝、银联和paypal。Gree...
lcloud怎么样?lcloud零云,UOVZ新开的子站,现在沪港iplc KVM VPS有端午节优惠,年付双倍流量,200Mbps带宽,性价比高。100Mbps带宽,500GB月流量,10个,512MB内存,优惠后月付70元,年付700元。另有国内独立服务器租用,泉州、佛山、成都、德阳、雅安独立服务器低至400元/月起!点击进入:lcloud官方网站地址lcloud零云优惠码:优惠码:bMVbR...
在之前的一些文章中有提到HostYun商家的信息,这个商家源头是比较老的,这两年有更换新的品牌域名。在陆续的有新增机房,价格上还是走的低价格路线,所以平时的折扣力度已经是比较低的。在前面我也有介绍到提供九折优惠,这个品牌商家就是走的低价量大为主。中秋节即将到,商家也有推出稍微更低的88折。全场88折优惠码:moon88这里,整理部分HostYun商家的套餐。所有的价格目前都是原价,我们需要用折扣码...
option82为你推荐
丑福晋男主角中毒眼瞎毁容,女主角被逼当丫鬟,应用自己的血做药引帮男主角解毒的言情小说百度关键词工具如何通过百度官方工具提升关键词排名haole10.com空人电影网改网址了?www.10yyy.cn是空人电影网么partnersonlinecashfiesta 该怎么使用啊~~机器蜘蛛求一个美国的科幻电影名!里面有大型的机械蜘蛛。www.175qq.com这表情是什么?www.javlibrary.com跪求一个JAVHD.com的帐号猴山条约中国近代史领土被割占去了多少,包括战争中失去的和吞并的总数两朝太岁冲犯太岁什么意思两朝太岁只恐太岁当头落 是什么意思?求解
域名管理 草根过期域名 bbr 主机点评 godaddy域名优惠码 云主机51web typecho dropbox网盘 私有云存储 怎么测试下载速度 流量计费 服务器监测 web服务器是什么 太原联通测速 国外的代理服务器 金主 域名转入 1美元 攻击服务器 ssl加速 更多