本文已被:浏览 889次 下载 1900次
Received:April 19, 2021 Revised:May 19, 2021
Received:April 19, 2021 Revised:May 19, 2021
中文摘要: BGP协议明文传输, 攻击者易对前缀与路径信息进行伪造, 进而引发危害巨大的前缀劫持攻击. 其中, AS路径信息保护问题主要涉及两个方面: 路径防篡改与非法内容验证. RPKI作为解决路由劫持的重要安全体系, 目前其体系下的路径验证解决方案主要包括BGPSec、ASPA与Path-End, 其中BGPSec主要解决的是路径篡改问题, ASPA与Path-End解决路径合法性验证问题, 而这些方案分别存在计算复杂或者路径保护力度较弱的缺陷. 在ASPA方案中引入少量签名, 可对路径篡改的限制粒度进行提升. 据此, 本文提出一种改进的路径保护机制, 并设计了与其余方案的开销、安全性能对比实验. 实验结果表明, 在引入有限开销的情况下, 改进机制的路径保护性能优于其余方案.
Abstract:In the BGP protocol plaintext transmission, attackers easily forge the prefix and path information, which thereby causes prefix hijacking with great harm. The AS path information protection mainly involves two aspects: path tamper-proofing and verification of illegal content. Resource public key infrastructure (RPKI) is an important security system to solve route hijacking. Currently, the path verification solutions under the RPKI system mainly include BGPSec, ASPA and Path-End, among which BGPSec mainly addresses path tampering, while ASPA and Path-End target path legality verification. However, these schemes have the defects of complicated calculation or weak path protection. A small number of signatures are introduced into the ASPA scheme to improve the granularity limiting path tampering. Therefore, this study proposes an improved path protection mechanism and designs comparison experiments with other schemes regarding the overhead and safety performance. The experimental results show that the performance of the improved scheme is better than that of the other schemes under the condition of introducing limited overhead.
keywords: BGP path validation RPKI ASPA BGPSec
文章编号: 中图分类号: 文献标志码:
基金项目:
引用文本:
包卓,马迪,毛伟,邵晴.基于RPKI-ASPA改进的BGP路径保护机制.计算机系统应用,2022,31(2):316-324
BAO Zhuo,MA Di,MAO Wei,SHAO Qing.Improved BGP Path Protection Mechanism Based on RPKI-ASPA.COMPUTER SYSTEMS APPLICATIONS,2022,31(2):316-324
包卓,马迪,毛伟,邵晴.基于RPKI-ASPA改进的BGP路径保护机制.计算机系统应用,2022,31(2):316-324
BAO Zhuo,MA Di,MAO Wei,SHAO Qing.Improved BGP Path Protection Mechanism Based on RPKI-ASPA.COMPUTER SYSTEMS APPLICATIONS,2022,31(2):316-324