首页> 外文会议>Cordless Office >Detection of invalid routing announcement in the Internet
【24h】

Detection of invalid routing announcement in the Internet

机译:在Internet中检测到无效的路由公告

获取原文
获取原文并翻译 | 示例

摘要

Network measurement has shown that a specific IP address prefix may be announced by more than one autonomous system (AS), a phenomenon commonly referred to as Multiple Origin AS, or MOAS. MOAS can be due to either operational need to support multi-homing, or false route announcements due to configuration or implementation errors, or even by intentional attacks. Packets following such bogus routes will be either dropped or in the case of an intentional attack, delivered to a machine of the attacker's choosing. The paper presents a protocol enhancement to BGP which enables BGP to detect bogus route announcements from false origins. Rather than imposing cryptography-based authentication and encryption to secure routing message exchanges, our solution makes use of the rich connectivity among ASs that exists in the Internet. Simulation results show that this simple solution can effectively detect false routing announcements even in the presence of multiple compromised routers, become more robust in larger topologies, and can substantially reduce the impact of false routing announcements even with a partial deployment.
机译:网络测量表明,特定的IP地址前缀可以由多个自治系统(AS)宣布,这种现象通常称为多源AS或MOAS。 MOAS可能是由于操作上需要支持多宿主,或者是由于配置或实现错误甚至是有意攻击而导致的错误路由通告。遵循此类伪造路由的数据包将被丢弃,或者在故意攻击的情况下,将其发送到攻击者选择的计算机。本文提出了对BGP的协议增强,使BGP能够检测来自错误来源的虚假路由通告。我们的解决方案没有使用基于密码的身份验证和加密来确保路由消息交换的安全,而是利用Internet中存在的AS之间的丰富连接。仿真结果表明,即使在存在多个受损路由器的情况下,这种简单的解决方案也可以有效检测虚假路由公告,在更大的拓扑结构中变得更加健壮,并且即使部分部署,也可以大大减少虚假路由公告的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号