浏览全部资源
扫码关注微信
1. 浙江省新型互联网交换中心有限公司,浙江 杭州 311200
2. 中国信息通信研究院,北京 100191
3. 华为技术有限公司,北京 100095
[ "叶朝阳(1976- ),男,浙江省新型互联网交换中心有限责任公司总经理、中国互联网协会互联网互联互通工作委员会副主任委员,主要研究方向为新型互联网交换中心网络架构与协议设计、云网交换等" ]
[ "沈辰(1989- ),中国信息通信研究院工程师,主要研究方向为互联网网络互联互通、互联网路由安全、互联网测量与性能分析等" ]
[ "黄明庆(1969- ),男,华为技术有限公司高级IP技术研究专家,主要研究方向为网络空间安全、互联网协议架构等" ]
[ "张士聪(1990- ),男,浙江省新型互联网交换中心有限责任公司技术部经理,主要研究方向为新型互联与网络架构" ]
[ "刘伊莎(1992- ),女,浙江省新型互联网交换中心有限责任公司IT工程师,主要研究方向为新型互联与网络架构信息化" ]
网络出版日期:2021-12,
纸质出版日期:2021-12-20
移动端阅览
叶朝阳, 沈辰, 黄明庆, 等. 互联网BGP路由可视及安全检测技术架构与实践[J]. 电信科学, 2021,37(12):110-120.
Chaoyang YE, Chen SHEN, Mingqing HUANG, et al. Architecture and practice of BGP internet routing visibility and security detection[J]. Telecommunications science, 2021, 37(12): 110-120.
叶朝阳, 沈辰, 黄明庆, 等. 互联网BGP路由可视及安全检测技术架构与实践[J]. 电信科学, 2021,37(12):110-120. DOI: 10.11959/j.issn.1000-0801.2021263.
Chaoyang YE, Chen SHEN, Mingqing HUANG, et al. Architecture and practice of BGP internet routing visibility and security detection[J]. Telecommunications science, 2021, 37(12): 110-120. DOI: 10.11959/j.issn.1000-0801.2021263.
边界网关协议(border gateway protocol,BGP)是支撑互联网50年来快速发展的核心协议,因早期设计考虑不足一直存在路由劫持、路由泄露等路由安全威胁漏洞。随着互联网应用日益深入,BGP 路由安全问题逐渐引起业界重视,边界网络安全防护意义重大。提出了一种BGP路由安全检测架构,通过推理构建全球BGP路由知识库实现互联网全局路由可视性,并基于此实现路由劫持、路由泄露等路由安全事件的准实时检测。通过在杭州交换中心部署实践,证明本系统可构造较完整的互联网全局路由知识库、实现较准确和实时的BGP路由安全事件检测。
Border Gateway Protocol (BGP) is the de facto inter-domain routing protocol of today’s global internet for exchanging routing information.However
it was supposed that all participants were reliable without generating routing security issues by mistakes or on purpose when BGP was designed 50 years ago.As Internet is getting involved in all aspects of our society
internet routing security is becoming the problems that couldn’t be ignored anymore.A general architecture was proposed which coved inference of BGP routing knowledge database and provided visibility of global internet routing.Detection of route security events such as routing hijacks and routing leaks were realized.The deployment shows that the system can provide good visibility of internet routing and precise detection of routing security events.
ZHAO X L , PEI D , et al . An Analysis of BGP Multiple Origin AS Conflicts [C ] // Proceedings of the 1st ACM SIGCOMM Workshop on Internet Measurement 2001 . New York:ACM Press , 2001 .
CHIN K W , . On the characteristics of BGP multiple origin AS conflicts [C ] // Proceedings of 2007 Australasian Telecommunication Networks and Applications Conference . Piscataway:IEEE Press , 2007 : 157 - 162 .
LUCKIE M , HUFFAKER B , DHAMDHERE A , et al . AS relationships,customer cones,and validation [C ] // Proceedings of the 2013 conference on Internet measurement conference . New York:ACM Press , 2013 .
LI Y C , SCOTT C et al . Stable and Practical AS Relationship Inference with ProbLink [C ] // Proceedings of 16th {USENIX}Symposium on Networked Systems Design and Implementation ({NSDI} 19) . 2019 : 581 - 598 .
GIOTSAS V , LUCKIE M , et al . Inferring Complex AS Relationships [C ] // Proceedings of the 2014 conference on Internet measurement conference . New York:ACM Press , 2014 .
FENG G Y , SESHAN S , STEENKISTE P , et al . PARI:a probabilistic approach to AS relationships inference [EB ] . 2019 .
JIN Z T , SHI X G , YANG Y , et al . TopoScope:recover AS relationships from fragmentary observations [C ] // Proceedings of the ACM Internet Measurement Conference . New York:ACM Press , 2020 .
0
浏览量
706
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构