IETF RFC 7492 PDF

IETF RFC 7492 PDF

Name:
IETF RFC 7492 PDF

Published Date:
03/01/2015

Status:
[ Active ]

Description:

Analysis of Bidirectional Forwarding Detection (BFD) Security According to the Keying and Authentication for Routing Protocols (KARP) Design Guidelines

Publisher:
Internet Engineering Task Force

Document status:
Active

Format:
Electronic (PDF)

Delivery time:
10 minutes

Delivery time (for Russian version):
200 business days

SKU:

Choose Document Language:
$9.6
Need Help?

Introduction

This document performs a gap analysis of the current state of Bidirectional Forwarding Detection [RFC5880] according to the requirements of KARP Design Guidelines [RFC6518]. Previously, the OPSEC working group has provided an analysis of cryptographic issues with BFD in "Issues with Existing Cryptographic Protection Methods for Routing Protocols" [RFC6039].

The existing BFD specifications provide a basic security solution. Key ID is provided so that the key used in securing a packet can be changed on demand. Two cryptographic algorithms (MD5 and SHA‐1) are supported for integrity protection of the control packets; the algorithms are both demonstrated to be subject to collision attacks. Routing protocols like "RIPv2 Cryptographic Authentication" [RFC4822], "IS‐IS Generic Cryptographic Authentication" [RFC5310], and "OSPFv2 HMAC‐SHA Cryptographic Authentication" [RFC5709] have started to use BFD for liveliness checks. Moving the routing protocols to a stronger algorithm while using a weaker algorithm for BFD would allow the attacker to bring down BFD in order to bring down the routing protocol. BFD therefore needs to match the routing While BFD uses a non‐decreasing, per‐packet sequence number to protect itself from intra‐connection replay attacks, it still leaves the protocol vulnerable to the inter‐session replay attacks.


Edition : 15
File Size : 1 file , 160 KB
Number of Pages : 9
Published : 03/01/2015

History


Related products

IETF RFC 2128
Published Date: 03/01/1997
Dial Control Management Information Base using SMIv2
$12.9

Best-Selling Products

HFES 100
Published Date: 01/01/2007
Human Factors Engineering of Computer Workstations
$28.5
HFES 200
Published Date: 01/01/2008
Human Factors Engineering of Software User Interfaces
$60
HFES 300
Published Date: 01/01/2004
Guidelines for Using Anthropometric Data in Product Design
$25.5
HFES HFES 400
Published Date: 01/01/2021
Human Readiness Level Scale in the System Development Process