###
计算机系统应用英文版:2022,31(2):316-324
本文二维码信息
码上扫一扫!
基于RPKI-ASPA改进的BGP路径保护机制
包卓1,2, 马迪1,2,3, 毛伟2,3, 邵晴3
(1.中国科学院 计算机网络信息中心, 北京 100190;2.中国科学院大学, 北京 100049;3.互联网域名系统北京市工程研究中心, 北京 100190)
Improved BGP Path Protection Mechanism Based on RPKI-ASPA
BAO Zhuo1,2, MA Di1,2,3, MAO Wei2,3, SHAO Qing3
(1.Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China;2.University of Chinese Academy of Sciences, Beijing 100049, China;3.Internet Domain Name System Beijing Engineering Research Center, Beijing 100190, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 889次   下载 1900
Received:April 19, 2021    Revised:May 19, 2021
中文摘要: BGP协议明文传输, 攻击者易对前缀与路径信息进行伪造, 进而引发危害巨大的前缀劫持攻击. 其中, AS路径信息保护问题主要涉及两个方面: 路径防篡改与非法内容验证. RPKI作为解决路由劫持的重要安全体系, 目前其体系下的路径验证解决方案主要包括BGPSec、ASPA与Path-End, 其中BGPSec主要解决的是路径篡改问题, ASPA与Path-End解决路径合法性验证问题, 而这些方案分别存在计算复杂或者路径保护力度较弱的缺陷. 在ASPA方案中引入少量签名, 可对路径篡改的限制粒度进行提升. 据此, 本文提出一种改进的路径保护机制, 并设计了与其余方案的开销、安全性能对比实验. 实验结果表明, 在引入有限开销的情况下, 改进机制的路径保护性能优于其余方案.
中文关键词: BGP  路径验证  RPKI  ASPA  BGPSec
Abstract:In the BGP protocol plaintext transmission, attackers easily forge the prefix and path information, which thereby causes prefix hijacking with great harm. The AS path information protection mainly involves two aspects: path tamper-proofing and verification of illegal content. Resource public key infrastructure (RPKI) is an important security system to solve route hijacking. Currently, the path verification solutions under the RPKI system mainly include BGPSec, ASPA and Path-End, among which BGPSec mainly addresses path tampering, while ASPA and Path-End target path legality verification. However, these schemes have the defects of complicated calculation or weak path protection. A small number of signatures are introduced into the ASPA scheme to improve the granularity limiting path tampering. Therefore, this study proposes an improved path protection mechanism and designs comparison experiments with other schemes regarding the overhead and safety performance. The experimental results show that the performance of the improved scheme is better than that of the other schemes under the condition of introducing limited overhead.
keywords: BGP  path validation  RPKI  ASPA  BGPSec
文章编号:     中图分类号:    文献标志码:
基金项目:
引用文本:
包卓,马迪,毛伟,邵晴.基于RPKI-ASPA改进的BGP路径保护机制.计算机系统应用,2022,31(2):316-324
BAO Zhuo,MA Di,MAO Wei,SHAO Qing.Improved BGP Path Protection Mechanism Based on RPKI-ASPA.COMPUTER SYSTEMS APPLICATIONS,2022,31(2):316-324