摘要
基于BGP的域间路由系统是互联网的核心基础设施。互联网不仅在数据转发性能方面,而且在拓扑结构、健壮性、安全性等方面也都高度依赖于域间路由系统。然而域间路由系统存在诸多安全缺陷且易遭受攻击,给互联网带来巨大安全隐患。从协议安全缺陷、结构脆弱性和路由设备架构缺陷3个方面分析域间路由系统的安全问题,并对已有的典型域间路由系统安全解决方案的基本原理、特点及适用性进行重点分析。
The BGP-based inter-domain routing system is a critical component of the Internet infra- structure. The performance of data forwarding, the topology, robustness, and security of the Internet, rely on the inter-domain routing system. Hence the vulnerability of the inter-domain routing system imposes threats to the Internet. This paper analyzes BGP protocol security, structure vulnerabilities, and routing equipment flaws, and discusses the basic principles, characteristics, and applicability of several existing inter-domain routing systems.
出处
《信息工程大学学报》
2012年第3期345-351,共7页
Journal of Information Engineering University
基金
国家973计划资助项目(2007CB307102)
关键词
BGP
域间路由系统
协议扩展
安全监测
BGP
inter-domain routing
protocol extension
security monitoring