Dynamic Access Control Lists for Multicast Source Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multicast routing protocols like PIM-SM and Bi-directional PIM lack effective protection against unauthorized sources, leading to bandwidth waste and denial-of-service attacks due to the shared distribution tree model, where malicious hosts can flood networks with multicast traffic.
Innovation Solution
Implementing dynamic access control lists in switching devices to deny forwarding of multicast packets from unauthorized sources by updating ACLs based on Internet Group Management Protocol (IGMP) messages and PIM joins, allowing only authorized hosts to send traffic, thereby filtering out unwanted traffic at the first hop router.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If shared distribution tree based multicast forwarding is used, then multicast traffic can be efficiently distributed to multiple receivers, but unauthorized malicious hosts can send multicast traffic at high rates causing bandwidth waste and denial of service attacks
Solution Approach 1:
The patent applies preliminary action by pre-configuring access control lists (ACLs) in switching devices to deny multicast traffic from unauthorized sources before the traffic can flood the network. The ACLs are dynamically updated based on admission-control messages, allowing legitimate sources to be permitted while blocking potential attackers in advance, thus preventing bandwidth waste and DOS attacks before they occur.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of admission-control messages (such as IGMP messages) that act as mediators between potential multicast sources and the network. These messages provide authentication information that switching devices use to verify source legitimacy, allowing the network to distinguish between authorized and unauthorized sources without affecting the efficiency of legitimate multicast distribution.
2Reliability
If access control lists are manually maintained to limit multicast sources, then unauthorized sources can be blocked, but the solution is not scalable
Solution Approach 1:
The patent applies dynamics by transforming static, manually configured access control lists into dynamic ACLs that automatically update based on admission-control messages. The ACLs are dynamically created, modified, and removed based on real-time authentication information from messages like IGMP, eliminating the need for manual configuration while maintaining security. This dynamic approach allows the system to adapt to changing network conditions and source legitimacy status automatically.
Solution Approach 2:
The patent implements self-service by enabling the network infrastructure to automatically manage source authorization without human intervention. Switching devices autonomously process admission-control messages, extract authentication information, and update their ACLs accordingly. This self-service mechanism eliminates the scalability limitations of manual configuration while maintaining reliable source control, as the system serves itself by automatically adapting to new sources and revoking access from unauthorized ones.
Data Source
AI summary
Disclosed are, inter alia, methods, apparatus, data structures, computer-readable media, and mechanisms for limiting unauthorized multicast sources. One or more access control lists are typically configured in a switching device to a state that denies forwarding of multicast packets with a particular host as its source. In response to a received multicast application admission-control message identifying the particular host, the one or more access control lists in the switching device are updated to allow multicast messages sent from the particular host to be forwarded. In one system, the received multicast application admission-control message is an Internet Group Management Protocol (IGMP) message. In response to the received multicast application admission-control message identifying the particular host, one system automatically adds one or more entries to the one or more access control lists to allow multicast traffic to be sent to and received from a next switching device leading to a corresponding multicast Rendezvous Point.


