首页> 外文会议>ACM conference on Computer and communications security >Origin authentication in interdomain routing
【24h】

Origin authentication in interdomain routing

机译:域间路由中的原始身份验证

获取原文

摘要

Attacks against Internet routing are increasing in number and severity. Contributing greatly to these attacks is the absence of origin authentication: there is no way to validate claims of address ownership or location. The lack of such services enables not only attacks by malicious entities, but indirectly allow seemingly inconsequential miconfigurations to disrupt large portions of the Internet. This paper considers the semantics, design, and costs of origin authentication in interdomain routing. We formalize the semantics of address delegation and use on the Internet, and develop and characterize broad classes of origin authentication proof systems. We estimate the address delegation graph representing the current use of IPv4 address space using available routing data. This effort reveals that current address delegation is dense and relatively static: as few as 16 entities perform 80% of the delegation on the Internet. We conclude by evaluating the proposed services via traced based simulation. Our simulation shows the enhanced proof systems can reduce significantly reduce resource costs associated with origin authentication.
机译:针对Internet路由的攻击数量和严重性都在增加。缺乏原始身份验证是造成这些攻击的主要原因:无法验证地址所有权或位置的声明。缺乏此类服务不仅使恶意实体能够进行攻击,而且还间接允许看似无关紧要的微配置破坏Internet的大部分。本文考虑了域间路由中源身份验证的语义,设计和成本。我们对地址委托和在Internet上使用的语义进行形式化,并开发和表征各种类型的原始身份验证证明系统。我们使用可用的路由数据估计地址委托图,该地址代表了IPv4地址空间的当前使用情况。这项工作表明,当前的地址委托是密集且相对静态的:只有16个实体在Internet上执行80%的委托。我们通过基于跟踪的仿真评估提议的服务来得出结论。我们的仿真显示,增强的证明系统可以减少与原产地认证相关的资源成本,从而大大降低成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号