首页> 外文期刊>Computer communication review >RPKI vs ROVER Comparing the Risks of BGP Security Solutions
【24h】

RPKI vs ROVER Comparing the Risks of BGP Security Solutions

机译:RPKI与ROVER比较BGP安全解决方案的风险

获取原文
获取原文并翻译 | 示例
           

摘要

BGP, the Internet's interdomain routing protocol, is highly vulnerable to routing failures that result from unintentional misconfigurations or deliberate attacks. To defend against these failures, recent years have seen the adoption of the Resource Public Key Infrastructure (RPKI), which currently authorizes 4% of the Internet's routes. The RPKI is a completely new security infrastructure (requiring new servers, caches, and the design of new protocols), a fact that has given rise to some controversy. Thus, an alternative proposal has emerged: Route Origin Verification (ROVER), which leverages the existing reverse DNS (rDNS) and DNSSEC to secure the interdomain routing system. Both RPKI and ROVER rely on a hierarchy of authorities to provide trusted information about the routing system. Recently, however, argued that the misconfigured, faulty or compromised RPKI authorities introduce new vulnerabilities in the routing system, which can take IP prefixes offline. Meanwhile, the designers of ROVER claim that it operates in a "fail-safe" mode, where "[o]ne could completely unplug a router verification application at any time and Internet routing would continue to work just as it does today". There has been debate in Internet community mailing lists about the pros and cons of both approaches. This poster therefore compares the impact of ROVER failures to those of the RPKI, in a threat model that covers misconfigurations, faults or compromises of their trusted authorities.
机译:BGP是Internet的域间路由协议,非常容易遭受由于意外的错误配置或蓄意的攻击而导致的路由故障。为了防御这些故障,近年来已经采用了资源公钥基础结构(RPKI),该方法目前授权4%的Internet路由。 RPKI是全新的安全性基础结构(需要新的服务器,缓存和新协议的设计),这一事实引起了一些争议。因此,出现了另一种建议:路由源验证(ROVER),它利用现有的反向DNS(rDNS)和DNSSEC来保护域间路由系统。 RPKI和ROVER都依赖于权限的层次结构来提供有关路由系统的受信任信息。但是,最近有人争辩说,错误配置,故障或受损的RPKI权限在路由系统中引入了新的漏洞,这些漏洞可使IP前缀脱机。同时,ROVER的设计者声称它以“故障安全”模式运行,其中“任何时候都可以完全拔掉路由器验证应用程序,Internet路由将继续像今天一样工作”。 Internet社区邮件列表中一直存在关于这两种方法的优缺点的辩论。因此,本海报在威胁模型中比较了ROVER故障与RPKI故障的影响,该威胁模型涵盖了错误配置,故障或受信任机构的破坏。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号