期刊文献+

域间路由系统安全技术研究 被引量:4

Research on Inter-Domain Routing System Security Techniques
下载PDF
导出
摘要 基于BGP的域间路由系统是互联网的核心基础设施。互联网不仅在数据转发性能方面,而且在拓扑结构、健壮性、安全性等方面也都高度依赖于域间路由系统。然而域间路由系统存在诸多安全缺陷且易遭受攻击,给互联网带来巨大安全隐患。从协议安全缺陷、结构脆弱性和路由设备架构缺陷3个方面分析域间路由系统的安全问题,并对已有的典型域间路由系统安全解决方案的基本原理、特点及适用性进行重点分析。 The BGP-based inter-domain routing system is a critical component of the Internet infra- structure. The performance of data forwarding, the topology, robustness, and security of the Internet, rely on the inter-domain routing system. Hence the vulnerability of the inter-domain routing system imposes threats to the Internet. This paper analyzes BGP protocol security, structure vulnerabilities, and routing equipment flaws, and discusses the basic principles, characteristics, and applicability of several existing inter-domain routing systems.
出处 《信息工程大学学报》 2012年第3期345-351,共7页 Journal of Information Engineering University
基金 国家973计划资助项目(2007CB307102)
关键词 BGP 域间路由系统 协议扩展 安全监测 BGP inter-domain routing protocol extension security monitoring
  • 相关文献

参考文献17

  • 1Barbir A, Murphy S, Yang Y. Generic Threats to Routing Protocols[ R]. IETF RFC 4593, 2006.
  • 2郭毅,王振兴.基于免疫理论的域间路由系统安全监测模型[EB/OL].[2012—02-01]http:WWW.Springerlink.corn/con—tent/17365022361142541.
  • 3GUO Yi, WANG Zhenxing, LUO Shaopeng, et al. A cascading failure model for interdomain routing system[ EB/OL]. [ 2012-02-01 ] http ://Onlinelibrary. wiley, com/doi/10. 1002/dac. 1307/full.
  • 4Kent S, Lynn C, Seo K. Secure border gateway protocol (S-BGP) [ J]. IEEE Journal on Selected Areas in Communications, 2000, 18(4): 582-592.
  • 5Seo K, Lynn C, Kent S. Public-key infrastructure for the secure border gateway protocol (S-BGP) [ C ]// Proceedings of DARPA Information Survivability Conference & Exposition II. 2001: 239-253.
  • 6White R. Securing BGP through secure origin BGP[J]. Internet Protocol Journal, 2003, 6(3) : 15-22.
  • 7Oorschot P C, Wan T, Kranakis E. On interdomain routing security and pretty secure BGP (psBGP) [ J]. ACM Transactions on Information and System Security (TISSEC) , 2007, 10(3) : 11-25.
  • 8Pei D, Mohit L, Beichuan Z. Route Diagnosis in Path Vector Protocols[ R]. UCLA CSD, 2004.
  • 9Mao. Validation of Multiple Origin ASes Conflicts through BGP Community Attribute [ S]. draft-zhao-idr-moasvalidation-00. txt.
  • 10Subramanian I, Roth V, Stoica I, et al. Listen and Whisper: Security Mechanisms for BGP[ C]//Proceedings of lth Sympo- sium on Networked Systems Design and Implementation(NSDI'04). 2004: 127-140.

二级参考文献22

  • 1Rekhter Y,Li T,Hares S.A border gateway protocol (BGP version 4).IETF Iuternet RFC,RFC 4274,2006.
  • 2Murphy S.BGP security vulnerabilities analysis.IETF Internet RFC,RFC 4272,2006.
  • 3Zhang Y,Zhang Z,Mao ZM,Hu C,Maggs BMD.On the impact of route monitor selection.In:Murai J,ed.Proc.of the 7th ACM SIGCOMM Conf.on Internet Measurement.New York:ACM Press,2007.215-220.[doi:10.1145/1298306.1298336].
  • 4Hu N,Zou P,Zhu PD.Cooperative management framework for inter-domain routing system.In:Rong C,ed.Proc.of the ATC 2008.LNCS 5060,Heidelberg:Springer-Verlag,2008.567-576.[doi:10.1007/978-3-540-69295-9_45].
  • 5Lu XC,Zhao JJ,Zhu PD,Dong P.Self-Organization of inter-domain routing system.Journal of Software,2006,17(9):1922-1932(in Chinese with English abstract),http://www.jos.org.cn/1000-9825/17/1922.htm[doi:10.1360/jos171922].
  • 6Internet routing registry.2009.http://www.irr.net/index.html.
  • 7The RIPE NCC MyASN service.2009.http://www.ris.ripe.net/myasn.html.
  • 8Looking glasses.2009.http://www.traceroute.org.
  • 9GRADUS.2009.http://www.renesys.com/index.shtml.
  • 10Georgos S,Michalis F.Analyzing BGP policies:Methodology and tool.In:Li VOK,ed.Proc.of the IEEE INFOCOM 2004.New York:IEEE Society Press,2004.1640-1651.[doi:10.1109/INFCOM.2004.1354576].

共引文献5

同被引文献24

引证文献4

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部