【24h】

A Reputation-Based Method to Secure Inter-Domain Routing

机译:一种基于信誉的方法来保护域间路由

获取原文

摘要

Due to the lack of the mechanism within BGP to verify the authority of an Autonomous System (AS) to announce Network Layer Reachable Information (NLRI), a specific IP prefix may be hijacked by a suspicious AS, leading to Internet instability even crash. Current proposals either are still no widely deployed for expensive overhead and complex key management, such as S-BGP, soBGP, etc, or can be incrementally deployed but not timely response and block attacks, just detect anomalies and rely on manual response from network operators, such as iSPY, PHAS, etc. The paper proposed an autonomous system origination reputation model to evaluate the trust degree of an autonomous system (AS) on originating the prefix. As a result, an AS selectively prefers the route announcement originated by the AS with higher origination reputation, prefix hijacking would be suppressed from happening. According to the beta reputation theory, the origination reputation of an AS is computed based on results of multiple prefix hijacking detection systems, by removing false positives and false negatives of detection systems. And the origination reputation is updated following the "slowly rising, quickly falling" principle. In the end, the validity of the model is verified by simulation experiments.
机译:由于BGP中缺乏机制来验证自主系统的权限(AS)宣布网络层可达信息(NLRI),可以通过可疑的AS劫持特定的IP前缀,从而导致互联网不稳定甚至崩溃。目前的建议仍然没有广泛用于昂贵的开销和复杂的密钥管理,例如S-BGP,Sobgp等,或者可以逐步地部署但不及时响应和阻止攻击,只能检测异常并依赖于网络运营商的手动响应,例如iSpy,PHA等。本文提出了一种自治系统,可以评估自主系统的信任程度(AS)源于前缀。因此,作为具有更高始发声誉的始发的路线通知,将抑制前缀劫持的作为源自较高的路线通知。根据Beta信誉理论,通过删除检测系统的假阳性和假否定的多个前缀劫持检测系统的结果来计算AS的起源声誉。并且在“慢慢上升,迅速下降”原则之后,起源是更新的。最后,通过仿真实验验证了模型的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号