Abstract: Security Considerations for Network Architecture

Avi Freedman, Akamai

Recent years have seen large-scale (though generally single-network) outages caused by misconfiguration, such as route redistribution, and/or software bugs. There is also concern that "properly" architected worm/virus attacks could create networks of hundreds of thousands or millions of devices that could be turned against the router infrastructure.

We will review some vulnerabilties that have been exposed in recent years, primarily relating to router CPU protection; route redistribution; router control/logging systems; the DNS infrastrucutre; and the robustness of interconnection between networks.

The presentation will review some common-knowledge fixes, and will discuss some interesting applications of network architecture and design that can help to mitigate serious vulnerabilities.

About the Presenter
Avi Freedman is Chief Network Scientist with Akamai, where he works on architecture, research, product development, Internet visualization, and vulnerability analysis. He is also on the board of FastNet, a network provider that recently acquired Netaxs. Prior to joining Akamai, Avi was VP of Engineering for AboveNet. He is also on the ARIN advisory council, and is actively involved in the network community.

PDF presentation
RealVideo stream