IPTV & Cisco Systems Korea Cisco Systems, Inc. All rights reserved. 1

Similar documents
임강빈 Cisco Systems Korea Cisco Systems, Inc. All rights reserved. 1

Configuring Private Hosts

MULTICAST SECURITY. Piotr Wojciechowski (CCIE #25543)

Massimiliano Sbaraglia

NETWORK THREATS DEMAN

Cisco 5921 Embedded Services Router

Private Hosts (Using PACLs)

Cisco ME 6524 Ethernet Switch

CCNA. Murlisona App. Hiralal Lane, Ravivar Karanja, Near Pethe High-School, ,

Cisco Certified Network Associate ( )

Implementing Cisco Network Security (IINS) 3.0

About the HP A7500 Configuration Guides

Fundamentals of Network Security v1.1 Scope and Sequence

Configuring Wireless Multicast

CCNA Routing and Switching (NI )

Cisco IOS IPv6. Cisco IOS IPv6 IPv6 IPv6 service provider IPv6. IPv6. data link IPv6 Cisco IOS IPv6. IPv6

Cisco ASR 5000 Series Small Cell Gateway

Cisco 5921 Embedded Services Router

CCIE Routing & Switching

About the H3C S5130-HI configuration guides

IPv6 IMPLEMENTATION IN VNPT

Cisco Exam. Volume: 223 Questions. Question No: 1 Which three commands can be used to harden a switch? (Choose three.)

DPX17000 Deep Service Core Switch

CISCO EXAM QUESTIONS & ANSWERS

TEXTBOOK MAPPING CISCO COMPANION GUIDES

Remote Access MPLS-VPNs

DGS-1510 Series Gigabit Ethernet SmartPro Switch Web UI Reference Guide. Figure 9-1 Port Security Global Settings window

Selected Network Security Technologies

JUNIPER JN0-643 EXAM QUESTIONS & ANSWERS

Chapter 5. Security Components and Considerations.

Alten Calsoft Labs Virtual B-RAS Solution

CISCO EXAM QUESTIONS & ANSWERS

Configuring IPv6 First-Hop Security

GS-2610G L2+ Managed GbE Switch

Catalyst 4500 Series IOS Commands

Internetwork Expert s CCNA Security Bootcamp. Common Security Threats

Exam Topics Cross Reference

AXILSPOT 48-Port 10-Gigabit L3 Managed Switch AS-MT48-L3

The IINS acronym to this exam will remain but the title will change slightly, removing IOS from the title, making the new title.

Chapter 11: Networks

S4600-SI Series L2 Gigabits Dual Stack Intelligent Switch Datasheet

Configuring Dynamic ARP Inspection

Gigabit Managed Ethernet Switch

Security Configuration Guide, Cisco IOS XE Everest 16.6.x (Catalyst 9300 Switches)

Configuring PIM Snooping

Overview. Features CHAPTER

PSGS-2610F L2+ Managed GbE PoE Switch

UniNets CCNA Security LAB MANUAL UNiNets CCNA Cisco Certified Network Associate Security LAB MANUAL UniNets CCNA LAB MANUAL

Module 5: Cisco Nexus 7000 Series Switch Administration, Management and Troubleshooting

About the H3C S5130-EI configuration guides

CCIE R&S LAB CFG H2/A5 (Jacob s & Jameson s)

Exam : Cisco Title : Update : Demo. Composite Exam

HP 6125 Blade Switch Series


Understanding and Configuring Dynamic ARP Inspection

DCS CT-POE fully loaded AT PoE Switch Datasheet

Configuring Dynamic ARP Inspection

Palo Alto Networks PCNSE7 Exam

FGS-2616X L2+ Managed GbE Fiber Switches

CERTIFICATE CCENT + CCNA ROUTING AND SWITCHING INSTRUCTOR: FRANK D WOUTERS JR. CETSR, CSM, MIT, CA

Modular Policy Framework. Class Maps SECTION 4. Advanced Configuration

Exam : Title : Security Solutions for Systems Engineers. Version : Demo

Cisco Systems Korea Cisco Systems, Inc. All rights reserved. 1

S5750E-SI Series L3 Lite Gigabits Dual Stack Intelligent Switch Datasheet

S5750E-SI Series L3 Lite Gigabits Dual Stack Intelligent Switch Datasheet

24-Port: 20 x (100/1000M) SFP + 4 x Combo (10/100/1000T or 100/1000M SFP)

S.No. CCIE Security Written Exam Topics v4.0 Part I Infrastructure, Connectivity, Communications, Network Security

Cisco EXAM Designing for Cisco Internetwork Solutions. Buy Full Product.

Configuring Control Plane Policing

H3C SR8800-F Core Routers

CCNP (Routing & Switching and T.SHOOT)

Fireware-Essentials. Number: Fireware Essentials Passing Score: 800 Time Limit: 120 min File Version: 7.

PassTorrent. Pass your actual test with our latest and valid practice torrent at once

Cisco Configuring Cisco Nexus 7000 Switches v3.1 (DCNX7K)

Case Study A Service Provider s Road to IPv6

Introduction to IGMP for IPTV Networks

Cisco ME 6524 Ethernet Switch

Configuring Control Plane Policing

Module Overview. works Identify NAP enforcement options Identify scenarios for NAP usage

Cisco Router Configuration Handbook

Security Assessment Checklist

Index. Numerics. Index 1

Configuration Guide TL-ER5120/TL-ER6020/TL-ER REV3.0.0

PrepAwayExam. High-efficient Exam Materials are the best high pass-rate Exam Dumps

Written by Alexei Spirin Wednesday, 02 January :06 - Last Updated Wednesday, 02 January :24

Chapter 11: It s a Network. Introduction to Networking

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

Cisco Self Defending Network

Cisco EXAM Cisco ADVDESIGN. Buy Full Product.

DPX19000 Next Generation Cloud-Ready Service Core Platform

Gigabit Managed Ethernet Switch

Gigabit Managed Ethernet Switch

User Guide TL-R470T+/TL-R480T REV9.0.2

CTO PoV: Enterprise Networks (Part 2) Security for IoT & Cloud

New methods to protect the network. Deeper visibility with Cisco NGFW Next Generation Firewall

Configure Multicast on Cisco Mobility Express AP's

DATASHEET. Advanced 6-Port Gigabit VPN Network Router. Model: ER-6. Sophisticated Routing Features. Advanced Security, Monitoring, and Management

Catalyst 4500 Series IOS Commands

Syllabus. Cisco Certified Design Professional. Implementing Cisco IP Routing

RADIUS Configuration Note WINS : Wireless Interoperability & Network Solutions

Transcription:

IPTV & (jaehakim@cisco.com) Cisco Systems Korea 2008 Cisco Systems, Inc. All rights reserved. 1

IPTV 2008 Cisco Systems, Inc. All rights reserved. 2

2008 Cisco Systems, Inc. All rights reserved. 3

IP platform 2007~ 2011 -To-TV 10 -To-PC 4 : http://www.cisco.com/en/us/solutions/collateral/ns341/ns525/ns537/ns705/ns827/white_paper_c11-481374.html 2008 Cisco Systems, Inc. All rights reserved. 4

EB/mo : http://www.cisco.com/en/us/solutions/collateral/ns341/ns525/ns537/ns705/ns827/white_paper_c11-481374.html 2008 Cisco Systems, Inc. All rights reserved. 5

Business Access Aggregation Distributed Edge Regional HE Core Acquisition Network Super HE Content Owner BRAS Residential IP Content Network External Partners RG RG MPLS PE Policy Servers e Internal Enterprise/NOC Untrusted Mostly Trusted Trusted Internet Peering Internet Untrusted 2008 Cisco Systems, Inc. All rights reserved. 6

ḯ ሒ Ḛ ᾢ!!! - Ḷ SP ᄚ ⒃ ẋ ᬊᕚᇚ ᇚ ย ⑶ ᑺᙺ ⑲ ㉚ ሒ ᚪ ⑲Ṗ ᕚ ᶿ - ⑶ ᬊ TV ᇯ リ ㉚ ၮ⑲ ẟ ᇯ ᶪ ᤚ Ὶ IPᙺ ମᤖ ᕚ ㉚ ሒ Ḛ ᾢ ⒎ 2008 Cisco Systems, Inc. All rights reserved. 7

IPTV 2008 Cisco Systems, Inc. All rights reserved. 8

IPTV IPTV DoS, IP Spoffing SP. CAS, DRM 2008 Cisco Systems, Inc. All rights reserved. 9

IPTV Ḛ ᾢ 4 Ẋ Ḷᾢ IP Source S Guard DHCP Authorization ย ⑶ ᑺ IP Source Guard DHCP A th i ti Authorization ၮ⑲ Ḻ ՐՍԱԨ Data Center Protection 2008 Cisco Systems, Inc. All rights reserved. 10

- CAS/DRM 2008 Cisco Systems, Inc. All rights reserved. 11

HE? IP, urpf, DDoS? 자료출처 : 2008.01 / KISA 인터넷침해사고동향및분석월보 2008 Cisco Systems, Inc. All rights reserved. 12

HE -DoS Cisco Guard/Detector DDoS (Static BGP) 2008 Cisco Systems, Inc. All rights reserved. 13

Leading Practice Category Disable Unnecessary Services Control Device Access Examples ICMP redirects, CDP, IP Source Routing TACACS+, Radius, Password Encryption Protects Against Threats Unauthorized Access Secure Ports and Interfaces Reconnaissance, Denial-of- Service Disable unused interfaces, Reconnaissance, Denial-of of- VLAN Pruning Service Secure Routing Infrastructure Secure Switching Infrastructure Control Resource Exhaustion Policy Enforcement MD5 Authentication, Route Filters Port Security, Storm Control Control Plane Policing (CoPP), Hardware-based Rate Limiters urpf Denial-of of-service Denial-of-Service Denial-of-Service IP Spoofing, Denial-of-Service 2008 Cisco Systems, Inc. All rights reserved. 14

- DA = 239.244.244.1 SA = 10.0.1.1 E0 Network Engineer Source ip access-list extended source permit igmp any any 6! IGMPv2 reports permit igmp any any 7! IGMPv2 leave deny igmp any any! Queries, PIMv1, DVMRP, deny pim any any! Hello, Join/Prune, BSR deny ip any 224.0.0.0/8! Source.. permit ip any any - Source ACL -IGMP Join Filtering 2008 Cisco Systems, Inc. All rights reserved. 15

IGMP? CPU/ unlimited IGM MP/MLD E ntries 0 IGMP/MLD Table max Total Memory Ut ilization Memory Resources Gasp! 0 Other Processes t1 t2 tn t1 t2 tn time time IGMP/MLD Valid Periodic IGMP/MLD Reports Malicious IGMP/MLD Reports IGMP/MLD table size can be limited globally or per interface. IPv4 IGMP Limit 12.2(15)T: ip igmp limit <1-64000> IPv6 MLD Limit 12.4(2)T: ip mld limit <1-64000> 2008 Cisco Systems, Inc. All rights reserved. 16

Goal Features Subscriber Identification DHCP Option 60, DHCP Option 82 Subscriber Authentication PPPoE or Web Portal (Using Radius) Subscriber Isolation Rogue DHCP Server MAC Forced Forwarding on DSLAM Private VLAN/PVLAN Edge on Switch DHCP Snooping IP address spoofing Limiting No. of Channels/IGMP/Multicast states DHCP Snooping + IP Source Guard (IPSG) on Switch IGMP State limits/max-groups & Multicast limits on Switch 2008 Cisco Systems, Inc. All rights reserved. 17

- IP Source Guard Cisco IP Source Guard - DHCP Snooping Port ACL - IP Spoofing DHCP Requests DHCP Responses DHCP Response DHCP Request Untrusted P1 P3 Trusted DHCP Server DHCP Snooping Function 2008 Cisco Systems, Inc. All rights reserved. 18

2008 Cisco Systems, Inc. All rights reserved. 19

? Firewalls and Router ACLs / Network Intrusion Detection Security Agents CCTV Centralized Security and Policy Management Identity, AAA, Access Control Servers and Certificate Authorities Encryption and Virtual Private Networks (VPN s) 2008 Cisco Systems, Inc. All rights reserved. 20

Cisco IP NGN APP PLICATION LAYER SERVICE LAYER LAYER ETWORK L NE GAMING DATA CENTER Service Exchange Customer Element PRESENCE- BASED TELEPHONY Access / Aggregation WEB SERVICES Intelligent t Edge SECURITY + + Transport MOBILE APPS INTELLIGENT NETWORKING IP CONTACT CENTER Open Framework for Enabling Triple Play on the Move (Data, Voice, Video, Mobility) Multiservice Core ering E R raffic Enginee L A Y E agement Tr I O N A L e BW Mana O P E R A T curity Serv ice Assuranc Sec 2008 Cisco Systems, Inc. All rights reserved. 21

CISCO - ( / / ) - Cisco IP NGN - - / - - 2008 Cisco Systems, Inc. All rights reserved. 22

? ( ) DPI 2008 Cisco Systems, Inc. All rights reserved. 23

2008 Cisco Systems, Inc. All rights reserved. 24

DPI (Deep Packet Inspection)? IP Packet Inspection & Control - application - - traffic actioin Ap pplication Su ubscriber Netw work Condit tion Mark Block Redirect Set QoS 2008 Cisco Systems, Inc. All rights reserved. 25

Deep Packet Inspection IP Application Subscriber Awareness IP, Application 2008 Cisco Systems, Inc. All rights reserved. 26

Self-Service Service Security Level and Content Filter Anti-Spam Anti-Virus Anti-X Content t URL Filtering Filtering AAA Broadband Policy Manager SEF BRAS/BNG ISG/SSG Service Control Engine Core Internet Security Self-Service Station Web Portal Patch Server Scan/Test SW Server 2008 Cisco Systems, Inc. All rights reserved. 27

CISCO IP NGN - + + - - - / DPI - - Revenue - URL Filtering,,, 2008 Cisco Systems, Inc. All rights reserved. 28

2008 Cisco Systems, Inc. All rights reserved. 29

ম IPTV Ḛ ᾢ ⓿⑶ ⑲ ੪ ᄖᝮ,, 㒆 HE DDoS ᙺ ㉚ ẒᗦṖ⑲ ⓿⒂ ሒ ମᤖ Ḛ ᾢ ḯ Ḷᾢ ମ ᤚ ᕚ ⑲ ᝮ, ⑲ Ẋ⒂ ẋ ᬊᕚᇚ ᇚ ᒳ ᒳ⑲ ੪ᄖᝮ, DPI ᤍ ᶪ ⒎ ᧂ ᒳ⑲ Ḷ ᬊᕚᇚ ᇚ Ὺ⒂ 2008 Cisco Systems, Inc. All rights reserved. 30