首页> 外文期刊>IEICE Transactions on Communications >SIR: A Secure Identifier-Based Inter-Domain Routing for Identifier/Locator Split Network
【24h】

SIR: A Secure Identifier-Based Inter-Domain Routing for Identifier/Locator Split Network

机译:SIR:用于标识符/定位器拆分网络的基于安全标识符的域间路由

获取原文
获取原文并翻译 | 示例
       

摘要

We present the design of a secure identifier-based inter-domain routing, SIR, for the identifier/locator split network. On the one hand, SIR is a distributed path-vector protocol inheriting the flexibility of BGR On the other hand, SIR separates ASes into several groups called trust groups, which assure the trust relationships among ASes by enforceable control and provides strict isolation properties to localize attacks and failures. Security analysis shows that SIR can provide control plane security that can avoid routing attacks including some smart attacks which S-BGP/soBGP can be deceived. Meanwhile, emulation experiments based on the current Internet topology with 47,000 ASes from the CAIDA database are presented, in which we compare the number of influenced ASes under attacks of subverting routing policy between SIR and S-BGP/BGP. The results show that, the number of influenced ASes decreases substantially by deploying SIR.
机译:我们提出了一种用于标识符/定位器拆分网络的基于标识符的安全域间路由SIR的设计。一方面,SIR是一种继承了BGR灵活性的分布式路径向量协议;另一方面,SIR将AS分为几个组,称为信任组,这些组通过强制控制来确保AS之间的信任关系,并提供严格的隔离属性以进行本地化攻击和失败。安全分析表明,SIR可以提供控制平面安全性,可以避免路由攻击,包括一些可以欺骗S-BGP / soBGP的智能攻击。同时,基于CAIDA数据库中的47,000个AS进行了基于当前Internet拓扑的仿真实验,其中我们比较了在SIR和S-BGP / BGP之间颠覆路由策略的攻击下受影响的AS的数量。结果表明,通过部署SIR,受影响的AS数量大大减少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号