期刊文献+

支持域间分布式分组过滤的BGP扩展 被引量:3

BGP Extension to Support Inter-Domain Distributed Packets Filtering
在线阅读 下载PDF
导出
摘要 可信任是下一代互联网的重要特征.目前,互联网的路由系统只按照分组的目的IP地址转发分组,携带虚假源IP地址的伪造分组也会被传输到目的地,这会在威胁接收方安全的同时,隐藏发送方的真实身份.可信任互联网的路由系统不仅需要能够正确地转发分组,而且能够验证分组来自正确的发送方.基于路由的域间分布式分组过滤是过滤伪造分组的有效方法.提出了BGP的路由选择通知功能扩展,为域间分组过滤提供过滤标准.在扩展的支持下,边界路由器能够鉴别进入本自治系统的分组的真实性,过滤掉伪造其他自治系统地址的分组.模拟结果表明,路由选择通知不会对BGP正常的路由功能产生负面影响,选择合理的路由选择时钟参数,可以在同时取得较小带宽开销和较快收敛速度的情况下,为域间分布式分组过滤提供支持. To be trustworthy is an important characteristic of the next generation Internet. The routing system of the present Internet forwards packets only according to the destination IP address. Forged packets with spoofed source IP address will also be forwarded to the destination, which impairs the security of receiver and conceals the real identity of the sender. The trustworthy Internet requires the routing system not only forward packets correctly, but also validate the packets from the real sender. Inter-domain distributed packet filtering is an effective method to filter out spoofed packets. This paper proposes to extend BGP with route selection notice to provide filtering criteria. With the support, border routers can validate incoming packets and filter the spoofed packets form false autonomous systems. Simulation result indicates BGP route selection notice does not impair the routing function of BGP, and both proper design acceptable bandwidth cost and fast convergence may be achieved simultaneously.
出处 《软件学报》 EI CSCD 北大核心 2007年第12期3048-3059,共12页 Journal of Software
基金 Supported by the National Natural Science Foundation of China under Grant No.60473082(国家自然科学基金) the National Basic Research Program of China under Grant No.2003CB314801(国家重点基础研究发展计划(973))
关键词 可信任互联网 边界网关协议 域间路由 分布式分组过滤 trustworthy Internet border gateway protocol (BGP) inter-domain routing distributed packets filtering
  • 相关文献

参考文献22

  • 1Park K, Lee H. On the effectiveness of route-based packet filtering for distributed DoS attack prevention in power-law Internets. Proc. of ACM SIGCOMM, 2001,31 (4): 15-26.
  • 2Rekhter Y, Li T. A border gateway protocol 4 (BGP-4). RFC 1771, 1995.
  • 3Labovitz C, Malan GR, Jahanian F. Internet routing instability. IEEE/ACM Trans. on Networking, 1998,6(5):515-527.
  • 4Griffin TG, Shepherd FB, Wilfong G. The stable paths problem and interdomain routing. IEEE/ACM Trans. on Networking, 2002, 10(2):232-243.
  • 5Labovitz C, Ahuja A, Bose A, Jahanian F. Delayed Internet routing convergence. IEEE/ACM Trans. on Networking, 2000,9(3): 293-306.
  • 6Gao L, Rexford J. Stable Internet routing without global coordination. IEEE/ACM Trans. on Networking, 2001,9(6):681-692.
  • 7Villamizar C, Chandra R, Govindan R. BGP route flap damping. RFC 2439, 1998.
  • 8Chen E. Route refresh capability for BGP-4. RFC 2918, 2000.
  • 9Afek Y, Bremler-Barr A, Schwarz S. Improved BGP convergence via ghost flushing, IEEE Journal on Selected Areas in Communications, 2004,22( 10): 1933-1948.
  • 10Chandrashekar J, Duan Z, Zhang ZL. Limiting path exploration in BGP. In: Proc. of the IEEE INFOCOM, Vol.4, IEEE Press, 2005, 2337-2348.

同被引文献20

  • 1王洪君,王瑞军,王大东,高远.基于过滤机制的抑制BGP路由表增长的方法[J].东北大学学报(自然科学版),2004,25(8):754-757. 被引量:1
  • 2张晓哲,卢锡城,苏金树.分布式BGP协议体系结构[J].国防科技大学学报,2006,28(3):77-82. 被引量:5
  • 3Huston G. Analyzing the Internet's BGP routing table[J].The Internet Protocol Journal, 2001,4( 1):1-10.
  • 4Xu Z, Meng X, Zhang L, et al. Impact of IPv4 address allocation practice on BGP routing table growth[A]//IEEE 18th Annual Workshop on Computer Communications[C]. New York, USA: IEEE press, 2003:172--178.
  • 5Rekhter Y, Li T. An architecture for IP address allocation with CIDR[S], RFC 1518,1993.
  • 6Fuller V, Li T, Yu J, etal. Classless Inter--Domain Routing(CIDR) .. An address assignment and aggregation strategy[S]. RFC 1519,1993.
  • 7Belloin S , Bush R , Griffin T G, et at. Slowing routing table growth by filtering based on address allocation policies [ EB/OL ] . [2001-06-20]http://www. research, art. com.
  • 8H Liu Reducing routing table size using ternary--CAM[J]// Proceedings of the 9th Symposium on High Performance Interconnects [C] Stanford, Calif, USA, 2001:69-7:3.
  • 9KARPILOVSKYE, REXFORD J. Using forgetful routing to control BGP table size[C]// Proceedings of 2nd Conference on Future Networking Technologies(CoNext2006). Lisbon, Portugal. 2006.
  • 10Rekhter Y, I,iT. A border gateway protocol4(BGP--4)[S]. RFC1771,1995.

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部