Title: The Generalized TTL Security Mechanism (GTSM)
Author(s): V. Gill, J. Heasley, D. Meyer.
Status: EXPERIMENTAL
Date: Feb 2004
Length: 23321
The use of a packet's Time to Live (TTL) (IPv4) or Hop Limit (IPv6) to protect a protocol stack from CPU-utilization based attacks has been proposed in many settings (see for example, RFC2461). This document generalizes these techniques for use by other protocols such as BGP (RFC1771), Multicast Source Discovery Protocol (MSDP), Bidirectional Forwarding Detection, and Label Distribution Protocol (LDP) (RFC3036). While the Generalized TTL Security Mechanism (GTSM) is most effective in protecting directly connected protocol peers, it can also provide a lower level of protection to multi-hop sessions. GTSM is not directly applicable to protocols employing flooding mechanisms (e.g., multicast), and use of multi-hop GTSM should be considered on a case-by-case basis.
|
|
|