发明名称 SPOOF CHECKING WITHIN A LABEL SWITCHING COMPUTER NETWORK
摘要 A label switching router (LSR) is described that spoof checks Multi-protocol Label Switching (MPLS) packets to prevent malicious or inadvertent injection of MPLS packets within a label switched path (LSP). The LSR ensures that MPLS packets received from an upstream label switching router (LSR) contain labels that were advertised to that upstream LSR. A software module associated with a signaling protocol, such as the Resource Reservation Protocol (RSVP), the Label Distribution Protocol (LDP), or the Border Gateway Protocol (BGP), is extended to utilize an MPLS forwarding table, and MPLS interface table, and a remote autonomous system table. A set of interfaces for which the label was advertised may be checked to determine whether an interface on which a packet was received is contained in the set of interfaces. The MPLS forwarding table may contain a spoof-check field used to specify one of several different types of spoof checks and to specify the set of interfaces.
申请公布号 US2009201934(A1) 申请公布日期 2009.08.13
申请号 US20090425591 申请日期 2009.04.17
申请人 JUNIPER NETWORKS, INC. 发明人 RIJSMAN BRUNO
分类号 H04L12/56 主分类号 H04L12/56
代理机构 代理人
主权项
地址