基于RPKI-ASPA改进的BGP路径保护机制
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:


Improved BGP Path Protection Mechanism Based on RPKI-ASPA
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    BGP协议明文传输, 攻击者易对前缀与路径信息进行伪造, 进而引发危害巨大的前缀劫持攻击. 其中, AS路径信息保护问题主要涉及两个方面: 路径防篡改与非法内容验证. RPKI作为解决路由劫持的重要安全体系, 目前其体系下的路径验证解决方案主要包括BGPSec、ASPA与Path-End, 其中BGPSec主要解决的是路径篡改问题, ASPA与Path-End解决路径合法性验证问题, 而这些方案分别存在计算复杂或者路径保护力度较弱的缺陷. 在ASPA方案中引入少量签名, 可对路径篡改的限制粒度进行提升. 据此, 本文提出一种改进的路径保护机制, 并设计了与其余方案的开销、安全性能对比实验. 实验结果表明, 在引入有限开销的情况下, 改进机制的路径保护性能优于其余方案.

    Abstract:

    In the BGP protocol plaintext transmission, attackers easily forge the prefix and path information, which thereby causes prefix hijacking with great harm. The AS path information protection mainly involves two aspects: path tamper-proofing and verification of illegal content. Resource public key infrastructure (RPKI) is an important security system to solve route hijacking. Currently, the path verification solutions under the RPKI system mainly include BGPSec, ASPA and Path-End, among which BGPSec mainly addresses path tampering, while ASPA and Path-End target path legality verification. However, these schemes have the defects of complicated calculation or weak path protection. A small number of signatures are introduced into the ASPA scheme to improve the granularity limiting path tampering. Therefore, this study proposes an improved path protection mechanism and designs comparison experiments with other schemes regarding the overhead and safety performance. The experimental results show that the performance of the improved scheme is better than that of the other schemes under the condition of introducing limited overhead.

    参考文献
    相似文献
    引证文献
引用本文

包卓,马迪,毛伟,邵晴.基于RPKI-ASPA改进的BGP路径保护机制.计算机系统应用,2022,31(2):316-324

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2021-04-19
  • 最后修改日期:2021-05-19
  • 录用日期:
  • 在线发布日期: 2022-01-28
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京海淀区中关村南四街4号 中科院软件园区 7号楼305房间,邮政编码:100190
电话:010-62661041 传真: Email:csa (a) iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号