首页> 外文会议>IEEE joint international computer science and information technology conference >RAMD: Route Authentication and Misdirection Detection Protocol
【24h】

RAMD: Route Authentication and Misdirection Detection Protocol

机译:RAMD:路由身份验证和误定向检测协议

获取原文

摘要

The internet was originally designed to be trustworthy, reliable and extensible, while its infrastructure, mainly the routing mechanisms, was not constructed with security in mind. Moreover, routers are subject to malicious attacks that can harm individual users and hinder network operations. One of the subtle attacks is that a malicious router may collaborate in the control-plane and leave routing protocols operating properly to bypass the control-plane countermeasures and then targets the data-plane. Thus, it could forward packets to routes that are inconsistent with advertised ones in the control-plane, leading to so-called "misdirection" attack. In this paper, we focus on the misdirection attack launched in data-plane phase and propose lightweight, efficient and secure route authentication and misdirection detection (RAMD) protocol to authenticate the forwarding route before delivering data, and detect malicious routers that could misdirect traffic within autonomous systems that apply link-state routing protocols (e.g. OSPF). RAMD doesn't require cryptographic operations at data-plane phase and has little communication and computation overhead. Moreover, it's able to detect and respond to both passive and active misdirection attacks. We believe our work is an important step in detecting and preventing misdirection attack.
机译:互联网最初被设计为可信任,可靠和可扩展,而其基础结构(主要是路由机制)在构建时并未考虑安全性。此外,路由器会遭受恶意攻击,这些恶意攻击可能会伤害单个用户并阻碍网络运行。一种微妙的攻击是,恶意路由器可能在控制平面中进行协作,并使路由协议正常运行,以绕过控制平面的对策,然后将其作为数据平面的目标。因此,它可能会将数据包转发到与控制平面中的广告路由不一致的路由,从而导致所谓的“误导”攻击。在本文中,我们将重点放在数据平面阶段发起的误定向攻击,并提出轻量,高效且安全的路由身份验证和误定向检测(RAMD)协议,以在传送数据之前对转发路由进行身份验证,并检测可能误导内部流量的恶意路由器。应用链路状态路由协议(例如OSPF)的自治系统。 RAMD不需要在数据平面阶段进行加密操作,并且通信和计算开销很小。此外,它能够检测并响应被动和主动的误导攻击。我们认为,我们的工作是检测和防止误导攻击的重要一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号