首页> 外文期刊>Computer networks >Autonomous security for autonomous systems
【24h】

Autonomous security for autonomous systems

机译:自治系统的自治安全

获取原文
获取原文并翻译 | 示例
           

摘要

The Internet's interdomain routing protocol, BGP, supports a complex network of Autonomous Systems which is vulnerable to a number of potentially crippling attacks. Several promising cryptography-based solutions have been proposed, but their adoption has been hindered by the need for community consensus, cooperation in a public key infrastructure (PKI), and a common security protocol. Rather than force centralized control in a distributed network, this paper examines distributed security methods that are amenable to incremental deployment. Typically, such methods are less comprehensive and not prov-ably secure. The paper describes a distributed anomaly detection and response system that provides comparable security to cryptographic methods and has a more plausible adoption path. Specifically, the paper makes the following contributions: (1) it describes pretty good BGP (PGBGP), whose security is comparable (but not identical) to secure origin BGP; (2) it gives theoretical proofs on the effectiveness of PGBGP; (3) it reports simulation experiments on a snapshot of the Internet topology annotated with the business relationships between neighboring networks; (4) it quantifies the impact that known exploits could have on the Internet; and (5) it determines the minimum number of ASes that would have to adopt a distributed security solution to provide global protection against these exploits. Taken together these results explore the boundary between what can be achieved with provably secure centralized security mechanisms for BGP and more distributed approaches that respect the autonomous nature of the Internet.
机译:互联网的域间路由协议BGP支持自治系统的复杂网络,该网络容易受到多种潜在的严重攻击。已经提出了几种有前途的基于密码学的解决方案,但是由于需要社区达成共识,在公钥基础结构(PKI)中进行合作以及使用通用安全协议而受到阻碍。本文不是在分布式网络中强制进行集中控制,而是研究适用于增量部署的分布式安全方法。通常,这样的方法不够全面,并且不能证明是安全的。本文介绍了一种分布式异常检测和响应系统,该系统可提供与加密方法相当的安全性,并且具有更合理的采用途径。具体来说,本文做出了以下贡献:(1)描述了相当不错的BGP(PGBGP),其安全性与安全来源BGP相当(但不完全相同); (2)为PGBGP的有效性提供了理论证明; (3)报告了有关Internet拓扑快照的仿真实验,该快照标注了相邻网络之间的业务关系; (4)量化已知漏洞可能对互联网产生的影响; (5)确定为采用针对这些漏洞的全局保护而必须采用分布式安全解决方案的最小数量的AS。总之,这些结果探索了可以证明的BGP安全集中式安全机制与尊重Internet自治特性的更分布式方法之间的界限。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号