PBS NSLP I-D (draft-hong-nsis-pbs-nslp)
Se Gi Hong <[email protected]>
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Organization | CS |
| Message-ID | <[email protected]> |
Hi all, We have submitted PBS NSLP I-D that is available at: http://www.ietf.org/internet-drafts/draft-hong-nsis-pbs-nslp-01.txt This document describes the NSIS Signaling Layer protocol (NSLP) for network traffic authorization in the Internet, the Permission-Based Sending (PBS) NSLP. This NSLP aims to prevent Denial-of-Service (DoS) attacks and other forms of unauthorized traffic. In the PBS NSLP, a receiver grants a sender a permission that gives the sender the authority to send data. Signaling installs and maintains the permission state of routers for a data flow. The PBS NSLP has a detection algorithm, the PBS Detection Algorithm (PDA), that monitors attacks. To authenticate packets, the PBS NSLP requests a sender to use an existing security protocol, the IPsec Authentication Header (AH). This allows routers to drop bogus packets by using an IP packet filter. To avoid a compromised router that drops legitimate packets, the PBS NSLP triggers the sender to change the data flow path. Thanks, SeGi Hong