首页> 外文期刊>ACM Transactions on Internet Technology >Comparing Ingress and Egress Detection to Secure Interdomain Routing: An Experimental Analysis
【24h】

Comparing Ingress and Egress Detection to Secure Interdomain Routing: An Experimental Analysis

机译:比较出入检测与安全域间路由:实验分析

获取原文
获取原文并翻译 | 示例
       

摘要

The global economy and society increasingly depends on computer networks linked together by the Internet. The importance of computer networks reaches far beyond the telecommunications sector since they have become a critical factor for many other crucial infrastructures and markets. With threats mounting and security incidents becoming more frequent, concerns about network security grow. It is an acknowledged fact that some of the most fundamental network protocols that make the Internet work are exposed to serious threats. One of them is the Border Gateway Protocol (BGP) which determines how Internet traffic is routed through the topology of administratively independent networks that the Internet is comprised of. Despite the existence of a steadily growing number of BGP security proposals, to date none of them has been adopted. Using a precise definition of BGP robustness we experimentally show that the degree of robustness is distributed unequally across the administrative domains of the Internet, the so-called Autonomous Systems (ASes). The experiments confirm the intuition that the contribution ASes are able to make towards securing the correct working of the inter-domain routing infrastructure by deploying countermeasures against routing attacks differ depending on their position in the AS topology. We also show that the degree of this asymmetry can be controlled by the choice of the security strategy. We compare the strengths and weaknesses of two fundamentally different approaches in increasing BGP's robustness which we termed ingress and egress detection of false route advertisements and indicate their implications. Our quantitative results have important implications for Internet security policy, in particular with respect to the crucial question where to start the deployment of which type of security scheme in order to maximize the Internet's robustness to routing attacks.
机译:全球经济和社会越来越依赖于通过Internet连接在一起的计算机网络。计算机网络的重要性已远远超出电信行业,因为它们已成为许多其他关键基础架构和市场的关键因素。随着威胁的增加和安全事件越来越频繁,对网络安全性的担忧也越来越多。公认的事实是,使Internet正常工作的一些最基本的网络协议面临着严重的威胁。其中之一是边界网关协议(BGP),它确定如何通过组成Internet的管理独立网络的拓扑来路由Internet流量。尽管BGP安全提议的数量在稳步增长,但迄今为止,尚未采纳任何提议。使用BGP鲁棒性的精确定义,我们实验证明了鲁棒性的程度在Internet的管理域(即所谓的自治系统(ASes))之间分布不均。实验证实了直觉,即AS能够通过部署针对路由攻击的对策来确保域间路由基础结构的正确运行,这取决于它们在AS拓扑中的位置。我们还表明,可以通过选择安全策略来控制这种不对称程度。我们比较了两种根本不同的方法在增强BGP鲁棒性方面的优缺点,我们将其称为错误路由通告的入口和出口检测,并指出了它们的含义。我们的定量结果对Internet安全策略具有重要意义,尤其是在关键问题上,即从何处开始部署哪种类型的安全方案,以最大程度地提高Internet对路由攻击的鲁棒性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号