Abstract :
[en] In Situ Operations, Administration, and Maintenance (IOAM) is an in-band telemetry protocol that enables network devices to embed operational telemetry data directly into the packet headers of user traffic. IOAM is designed to operate within a Limited Domain, i.e., an isolated and self-managed network environment protected by strict filtering mechanisms such as firewalls. However, this assumption may not hold in real-world deployments, where misconfigurations can expose the network to a range of security threats — an aspect that has
received limited attention from the research community. In this paper, we present a systematic security analysis of IOAM within Limited Domain environments, covering deployments such as Internet Service Provider networks and cloud infrastructures. We define a comprehensive threat model and identify concrete attack scenarios, including topology reconnaissance, telemetry poisoning, and denial-of-service attacks. We experimentally demonstrate the feasibility of these attacks in a controlled laboratory environment and discuss their potential impacts. We further propose and evaluate mitigation strategies, culminating in a kernel-level implementation that secures IOAM
data through encryption and authentication, thereby providing strong confidentiality and integrity guarantees.