首页> 外文期刊>Networking, IEEE/ACM Transactions on >Secure and Policy-Compliant Source Routing
【24h】

Secure and Policy-Compliant Source Routing

机译:安全且符合政策的源路由

获取原文
获取原文并翻译 | 示例
       

摘要

In today's Internet, inter-domain route control remains elusive; nevertheless, such control could improve the performance, reliability, and utility of the network for end users and ISPs alike. While researchers have proposed a number of source routing techniques to combat this limitation, there has thus far been no way for independent ASes to ensure that such traffic does not circumvent local traffic policies, nor to accurately determine the correct party to charge for forwarding the traffic. We present Platypus, an authenticated source routing system built around the concept of network capabilities, which allow for accountable, fine-grained path selection by cryptographically attesting to policy compliance at each hop along a source route. Capabilities can be composed to construct routes through multiple ASes and can be delegated to third parties. Platypus caters to the needs of both end users and ISPs: users gain the ability to pool their resources and select routes other than the default, while ISPs maintain control over where, when, and whose packets traverse their networks. We describe the design and implementation of an extensive Platypus policy framework that can be used to address several issues in wide-area routing at both the edge and the core, and evaluate its performance and security. Our results show that incremental deployment of Platypus can achieve immediate gains.
机译:在当今的Internet中,域间路由控制仍然难以实现。但是,这样的控制可以为最终用户和ISP改善网络的性能,可靠性和实用性。尽管研究人员提出了多种源路由技术来克服此限制,但迄今为止,独立AS尚无办法确保此类流量不会绕过本地流量策略,也无法准确确定转发流量的正确参与者。我们介绍Platypus,这是一种经过验证的源路由系统,它基于网络功能的概念而构建,该系统通过加密证明源路由的每一跳上的策略合规性,可以进行负责任的细粒度路径选择。可以组合能力以构建通过多个AS的路由,并可以将其委派给第三方。鸭嘴兽可以同时满足最终用户和ISP的需求:用户可以集中其资源并选择默认路由以外的路由,而ISP可以控制在何处,何时以及谁的数据包通过其网络。我们描述了一个广泛的鸭嘴兽政策框架的设计和实现,该框架可用于解决边缘和核心区域广域路由中的几个问题,并评估其性能和安全性。我们的结果表明,鸭嘴兽的逐步部署可以立即获得收益。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号