Title: Security Framework for Provider-ProvisionedVirtual Private Networks (PPVPNs)
Author(s): L. Fang, Ed.
Status: Informational
Date: July 2005
Pages: 45
Updates/Obsoletes/SeeAlso: None
URL: ftp://ftp.rfc-editor.org/in-notes/rfc4111.txt
This document addresses security aspects pertaining to Provider-Provisioned Virtual Private Networks (PPVPNs). First, it describes the security threats in the context of PPVPNs and defensive techniques to combat those threats. It considers security issues deriving both from malicious behavior of anyone and from negligent or incorrect behavior of the providers. It also describes how these security attacks should be detected and reported. It then discusses possible user requirements for security of a PPVPN service. These user requirements translate into corresponding provider requirements. In addition, the provider may have additional requirements to make its network infrastructure secure to a level that can meet the PPVPN customer's expectations. Finally, this document defines a template that may be used to describe and analyze the security characteristics of a specific PPVPN technology.