中文

基于RPKI的BGP路由起源验证中无效前缀的分类与误报分析

网络与互联网体系结构 2019-03-19 v1

摘要

BGP是当今互联网默认的域间路由协议,但存在严重安全漏洞\cite{murphy2005bgp}。其中之一是(子)前缀劫持。IETF标准化了RPKI以验证AS起源,但RPKI存在诸多问题\cite{heilman2014consent}\cite{cooper2013risk}\cite{gilad2017we}\cite{gilad2017maxlength},其中之一是潜在误报。尽管已有一些工作\cite{gilad2017we}\cite{heilman2014consent}或明确或隐含地指出该问题,进一步的测量与分析仍有待开展。我们的工作对无效前缀进行了系统测量与分析。我们首先将无效前缀分为六类,进而分析其稳定性。我们表明,很大比例的无效前缀极有可能源于流量工程、IP地址转移及未能聚合,而非真实劫持。

关键词

引用

@article{arxiv.1903.06860,
  title  = {On the classification and false alarm of invalid prefixes in RPKI based BGP route origin validation},
  author = {Wenjie Xu and Deliang Chang and Xing Li},
  journal= {arXiv preprint arXiv:1903.06860},
  year   = {2019}
}

备注

Accepted into IFIP/IEEE International Symposium on Integrated Network Management(IM) 2019 as a short paper