IPTV & (jaehakim@cisco.com) Cisco Systems Korea 2008 Cisco Systems, Inc. All rights reserved. 1
IPTV 2008 Cisco Systems, Inc. All rights reserved. 2
2008 Cisco Systems, Inc. All rights reserved. 3
IP platform 2007~ 2011 -To-TV 10 -To-PC 4 : http://www.cisco.com/en/us/solutions/collateral/ns341/ns525/ns537/ns705/ns827/white_paper_c11-481374.html 2008 Cisco Systems, Inc. All rights reserved. 4
EB/mo : http://www.cisco.com/en/us/solutions/collateral/ns341/ns525/ns537/ns705/ns827/white_paper_c11-481374.html 2008 Cisco Systems, Inc. All rights reserved. 5
Business Access Aggregation Distributed Edge Regional HE Core Acquisition Network Super HE Content Owner BRAS Residential IP Content Network External Partners RG RG MPLS PE Policy Servers e Internal Enterprise/NOC Untrusted Mostly Trusted Trusted Internet Peering Internet Untrusted 2008 Cisco Systems, Inc. All rights reserved. 6
ḯ ሒ Ḛ ᾢ!!! - Ḷ SP ᄚ ⒃ ẋ ᬊᕚᇚ ᇚ ย ⑶ ᑺᙺ ⑲ ㉚ ሒ ᚪ ⑲Ṗ ᕚ ᶿ - ⑶ ᬊ TV ᇯ リ ㉚ ၮ⑲ ẟ ᇯ ᶪ ᤚ Ὶ IPᙺ ମᤖ ᕚ ㉚ ሒ Ḛ ᾢ ⒎ 2008 Cisco Systems, Inc. All rights reserved. 7
IPTV 2008 Cisco Systems, Inc. All rights reserved. 8
IPTV IPTV DoS, IP Spoffing SP. CAS, DRM 2008 Cisco Systems, Inc. All rights reserved. 9
IPTV Ḛ ᾢ 4 Ẋ Ḷᾢ IP Source S Guard DHCP Authorization ย ⑶ ᑺ IP Source Guard DHCP A th i ti Authorization ၮ⑲ Ḻ ՐՍԱԨ Data Center Protection 2008 Cisco Systems, Inc. All rights reserved. 10
- CAS/DRM 2008 Cisco Systems, Inc. All rights reserved. 11
HE? IP, urpf, DDoS? 자료출처 : 2008.01 / KISA 인터넷침해사고동향및분석월보 2008 Cisco Systems, Inc. All rights reserved. 12
HE -DoS Cisco Guard/Detector DDoS (Static BGP) 2008 Cisco Systems, Inc. All rights reserved. 13
Leading Practice Category Disable Unnecessary Services Control Device Access Examples ICMP redirects, CDP, IP Source Routing TACACS+, Radius, Password Encryption Protects Against Threats Unauthorized Access Secure Ports and Interfaces Reconnaissance, Denial-of- Service Disable unused interfaces, Reconnaissance, Denial-of of- VLAN Pruning Service Secure Routing Infrastructure Secure Switching Infrastructure Control Resource Exhaustion Policy Enforcement MD5 Authentication, Route Filters Port Security, Storm Control Control Plane Policing (CoPP), Hardware-based Rate Limiters urpf Denial-of of-service Denial-of-Service Denial-of-Service IP Spoofing, Denial-of-Service 2008 Cisco Systems, Inc. All rights reserved. 14
- DA = 239.244.244.1 SA = 10.0.1.1 E0 Network Engineer Source ip access-list extended source permit igmp any any 6! IGMPv2 reports permit igmp any any 7! IGMPv2 leave deny igmp any any! Queries, PIMv1, DVMRP, deny pim any any! Hello, Join/Prune, BSR deny ip any 224.0.0.0/8! Source.. permit ip any any - Source ACL -IGMP Join Filtering 2008 Cisco Systems, Inc. All rights reserved. 15
IGMP? CPU/ unlimited IGM MP/MLD E ntries 0 IGMP/MLD Table max Total Memory Ut ilization Memory Resources Gasp! 0 Other Processes t1 t2 tn t1 t2 tn time time IGMP/MLD Valid Periodic IGMP/MLD Reports Malicious IGMP/MLD Reports IGMP/MLD table size can be limited globally or per interface. IPv4 IGMP Limit 12.2(15)T: ip igmp limit <1-64000> IPv6 MLD Limit 12.4(2)T: ip mld limit <1-64000> 2008 Cisco Systems, Inc. All rights reserved. 16
Goal Features Subscriber Identification DHCP Option 60, DHCP Option 82 Subscriber Authentication PPPoE or Web Portal (Using Radius) Subscriber Isolation Rogue DHCP Server MAC Forced Forwarding on DSLAM Private VLAN/PVLAN Edge on Switch DHCP Snooping IP address spoofing Limiting No. of Channels/IGMP/Multicast states DHCP Snooping + IP Source Guard (IPSG) on Switch IGMP State limits/max-groups & Multicast limits on Switch 2008 Cisco Systems, Inc. All rights reserved. 17
- IP Source Guard Cisco IP Source Guard - DHCP Snooping Port ACL - IP Spoofing DHCP Requests DHCP Responses DHCP Response DHCP Request Untrusted P1 P3 Trusted DHCP Server DHCP Snooping Function 2008 Cisco Systems, Inc. All rights reserved. 18
2008 Cisco Systems, Inc. All rights reserved. 19
? Firewalls and Router ACLs / Network Intrusion Detection Security Agents CCTV Centralized Security and Policy Management Identity, AAA, Access Control Servers and Certificate Authorities Encryption and Virtual Private Networks (VPN s) 2008 Cisco Systems, Inc. All rights reserved. 20
Cisco IP NGN APP PLICATION LAYER SERVICE LAYER LAYER ETWORK L NE GAMING DATA CENTER Service Exchange Customer Element PRESENCE- BASED TELEPHONY Access / Aggregation WEB SERVICES Intelligent t Edge SECURITY + + Transport MOBILE APPS INTELLIGENT NETWORKING IP CONTACT CENTER Open Framework for Enabling Triple Play on the Move (Data, Voice, Video, Mobility) Multiservice Core ering E R raffic Enginee L A Y E agement Tr I O N A L e BW Mana O P E R A T curity Serv ice Assuranc Sec 2008 Cisco Systems, Inc. All rights reserved. 21
CISCO - ( / / ) - Cisco IP NGN - - / - - 2008 Cisco Systems, Inc. All rights reserved. 22
? ( ) DPI 2008 Cisco Systems, Inc. All rights reserved. 23
2008 Cisco Systems, Inc. All rights reserved. 24
DPI (Deep Packet Inspection)? IP Packet Inspection & Control - application - - traffic actioin Ap pplication Su ubscriber Netw work Condit tion Mark Block Redirect Set QoS 2008 Cisco Systems, Inc. All rights reserved. 25
Deep Packet Inspection IP Application Subscriber Awareness IP, Application 2008 Cisco Systems, Inc. All rights reserved. 26
Self-Service Service Security Level and Content Filter Anti-Spam Anti-Virus Anti-X Content t URL Filtering Filtering AAA Broadband Policy Manager SEF BRAS/BNG ISG/SSG Service Control Engine Core Internet Security Self-Service Station Web Portal Patch Server Scan/Test SW Server 2008 Cisco Systems, Inc. All rights reserved. 27
CISCO IP NGN - + + - - - / DPI - - Revenue - URL Filtering,,, 2008 Cisco Systems, Inc. All rights reserved. 28
2008 Cisco Systems, Inc. All rights reserved. 29
ম IPTV Ḛ ᾢ ⓿⑶ ⑲ ੪ ᄖᝮ,, 㒆 HE DDoS ᙺ ㉚ ẒᗦṖ⑲ ⓿⒂ ሒ ମᤖ Ḛ ᾢ ḯ Ḷᾢ ମ ᤚ ᕚ ⑲ ᝮ, ⑲ Ẋ⒂ ẋ ᬊᕚᇚ ᇚ ᒳ ᒳ⑲ ੪ᄖᝮ, DPI ᤍ ᶪ ⒎ ᧂ ᒳ⑲ Ḷ ᬊᕚᇚ ᇚ Ὺ⒂ 2008 Cisco Systems, Inc. All rights reserved. 30