Hardening a control plane

Hey Folks,

I'm looking for information on various core network architectures that
could harden a control plane or prevent/isolate the propagation of say a
malformed packet/control plane issue. I know that a part of the problem
can be solved with edge filtering, ebgp, defense in depth and MD5 auth,
but I am looking for a solution that might involve multi-level IS-IS.

Any pointers would be a help.