How do you put a TV station on the Mbone?
tony at lavanauts.org
Thu May 5 16:26:48 UTC 2011
On Wed, 4 May 2011, George Bonser wrote:
>> SSM with encryption?
> Well, certainly, but source address can be very easily spoofed with a
> UDP multicast stream. Now that could be mitigated with a lot of network
> configuration rules but something is needed that just works without all
It's harder to effectively use spoofed source addresses in multicasting
because of RPF. When you couple it with SSM you're forcing the attacker
to either use multiple injection points, or gain access to a router close
to the real source address. Couple that with encryption and you're
denying spoofed addresses as an effective intrusion venue for large groups
of viewers listening to a specific SSM source.
Perfect is the enemy of good.
e-mail: tony at lavanauts.org
xmpp: antonioquerubin at gmail.com
More information about the NANOG