首页> 外文会议>Annual IEEE/IFIP International Conference on Dependable Systems and Networks >Practical Experience: Methodologies for Measuring Route Origin Validation
【24h】

Practical Experience: Methodologies for Measuring Route Origin Validation

机译:实践经验:路线起点验证的测量方法

获取原文

摘要

Performing Route Origin Validation (ROV) to filter BGP announcements, which contradict Route Origin Authorizations (ROAs) is critical for protection against BGP prefix hijacks. Recent works quantified ROV enforcing Autonomous Systems (ASes) using control-plane experiments. In this work we show that control-plane experiments do not provide accurate information about ROV-enforcing ASes. We devise data-plane approaches for evaluating ROV in the Internet and perform both control and data-plane experiments using different data acquisition sources. We analyze and correlate the results of our study to identify the number of ASes enforcing ROV, and hence protected with RPKI. We perform simulations with the ROV-enforcing ASes that we identified, and find that their impact on the Internet security against prefix hijacks is negligible. As a countermeasure we provide recommendations how to cope with the main factor hindering wide adoption of ROV.
机译:执行路由源验证(ROV)来过滤BGP公告,这与路由源授权(ROA)相矛盾,这对于防止BGP前缀劫持至关重要。最近的工作使用控制平面实验量化了执行自主系统(ASes)的ROV。在这项工作中,我们表明控制平面实验无法提供有关ROV实施AS的准确信息。我们设计了用于评估Internet中ROV的数据平面方法,并使用不同的数据采集源执行控制和数据平面实验。我们分析并关联我们的研究结果,以确定执行ROV并因此受到RPKI保护的AS的数量。我们使用识别出的支持ROV的AS执行模拟,发现它们对前缀劫持对Internet安全的影响可以忽略不计。作为对策,我们为如何应对阻碍ROV广泛采用的主要因素提供了建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号