首页> 外文期刊>ACM Transaction on Information and System Security >On Interdomain Routing Security and Pretty Secure BGP (psBGP)
【24h】

On Interdomain Routing Security and Pretty Secure BGP (psBGP)

机译:关于域间路由安全性和相当安全的BGP(psBGP)

获取原文
获取原文并翻译 | 示例

摘要

It is well known that the Border Gateway Protocol (BGP), the IETF standard interdomain routing protocol, is vulnerable to a variety of attacks, and that a single misconfigured or malicious BGP speaker could result in large-scale service disruption. In this paper, we present Pretty Secure BGP (psBGP)—a proposal for securing BGP, including an architectural overview, design details for significant aspects, and preliminary security and operational analysis. psBGP differs from other security proposals (e.g., S-BGP and soBGP) in that it makes use of a single-level PKI for AS number authentication, a decentralized trust model for verifying the propriety of IP prefix origin, and a rating-based stepwise approach for AS_PATH (integrity) verification. psBGP trades off the strong security guarantees of S-BGP for presumed-simpler operation, e.g., using a PKI with a simple structure, with a small number of certificate types, and of manageable size. psBGP is designed to successfully defend against various (nonmalicious and malicious) threats from uncoordinated BGP speakers, and to be incrementally deployed with incremental benefits.
机译:众所周知,边界网关协议(BGP)是IETF标准的域间路由协议,很容易受到各种攻击,并且单个配置错误或恶意的BGP扬声器可能导致大规模服务中断。在本文中,我们提出了相当安全的BGP(psBGP)-一种保护BGP的建议,包括体系结构概述,重要方面的设计细节以及初步的安全性和运营分析。 psBGP与其他安全提议(例如S-BGP和soBGP)的不同之处在于,它使用单级PKI进行AS号码身份验证,分散式信任模型(用于验证IP前缀起源的适当性)以及基于等级的逐步AS_PATH(完整性)验证的方法。 psBGP会折衷S-BGP的强大安全性保证,以实现假定的更简单的操作,例如,使用结构简单,证书类型少且大小可管理的PKI。 psBGP旨在成功防御来自不协调的BGP发言人的各种(非恶意和恶意)威胁,并以增量收益的方式逐步部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号