Diagnosis of route leaks among autonomous systems in the Internet

M. S. Siddiqui, D. Montero, M. Yannuzzi, R. Serral-Gracià, Xavi Masip-Bruin
{"title":"Diagnosis of route leaks among autonomous systems in the Internet","authors":"M. S. Siddiqui, D. Montero, M. Yannuzzi, R. Serral-Gracià, Xavi Masip-Bruin","doi":"10.1109/SACONET.2014.6867765","DOIUrl":null,"url":null,"abstract":"Border Gateway Protocol (BGP) is the defacto inter-domain routing protocol in the Internet. It was designed without an inherent security mechanism and hence is prone to a number of vulnerabilities which can cause large scale disruption in the Internet. Route leak is one such inter-domain routing security problem which has the potential to cause wide-scale Internet service failure. Route leaks occur when Autonomous systems violate export policies while exporting routes. As BGP security has been an active research area for over a decade now, several security strategies were proposed, some of which either advocated complete replacement of the BGP or addition of new features in BGP, but they failed to achieve global acceptance. Even the most recent effort in this regard, lead by the Secure Inter-Domain Routing (SIDR) working group (WG) of IETF fails to counter all the BGP anomalies, especially route leaks. In this paper we look at the efforts in countering the policy related BGP problems and provide an analytical insights into why they are ineffective. We contend a new direction for future research in managing the broader security issues in the inter-domain routing. In that light, we propose a naive approach for countering the route leak problem by analyzing the information available at hand, such as the RIB of the router. The main purpose of this paper was to position and highlight the autonomous smart analytical approach for tackling policy related BGP security issues.","PeriodicalId":440592,"journal":{"name":"2014 International Conference on Smart Communications in Network Technologies (SaCoNeT)","volume":"44 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-06-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 International Conference on Smart Communications in Network Technologies (SaCoNeT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SACONET.2014.6867765","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Border Gateway Protocol (BGP) is the defacto inter-domain routing protocol in the Internet. It was designed without an inherent security mechanism and hence is prone to a number of vulnerabilities which can cause large scale disruption in the Internet. Route leak is one such inter-domain routing security problem which has the potential to cause wide-scale Internet service failure. Route leaks occur when Autonomous systems violate export policies while exporting routes. As BGP security has been an active research area for over a decade now, several security strategies were proposed, some of which either advocated complete replacement of the BGP or addition of new features in BGP, but they failed to achieve global acceptance. Even the most recent effort in this regard, lead by the Secure Inter-Domain Routing (SIDR) working group (WG) of IETF fails to counter all the BGP anomalies, especially route leaks. In this paper we look at the efforts in countering the policy related BGP problems and provide an analytical insights into why they are ineffective. We contend a new direction for future research in managing the broader security issues in the inter-domain routing. In that light, we propose a naive approach for countering the route leak problem by analyzing the information available at hand, such as the RIB of the router. The main purpose of this paper was to position and highlight the autonomous smart analytical approach for tackling policy related BGP security issues.
Internet自治系统间路由泄漏诊断
边界网关协议BGP (Border Gateway Protocol)是Internet上事实上的域间路由协议。它的设计没有固有的安全机制,因此容易出现一些漏洞,从而导致互联网的大规模中断。路由泄漏就是这样一种域间路由安全问题,它有可能导致大规模的互联网服务故障。当自治系统在导出路由时违反导出策略时,就会发生路由泄漏。由于BGP安全是一个活跃的研究领域,十多年来,人们提出了几种安全策略,其中一些策略主张完全替换BGP或在BGP中添加新功能,但未能得到全球的接受。即使是IETF的安全域间路由工作组(Secure Inter-Domain Routing, WG)最近在这方面所做的努力,也未能应对所有的BGP异常,尤其是路由泄漏。在本文中,我们着眼于应对与政策相关的BGP问题的努力,并提供了分析性见解,以解释它们为什么无效。我们认为在管理域间路由中更广泛的安全问题是未来研究的新方向。鉴于此,我们提出了一种简单的方法,通过分析手头可用的信息来解决路由泄漏问题,例如路由器的RIB。本文的主要目的是定位和强调解决与策略相关的BGP安全问题的自主智能分析方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信