On interdomain routing security and pretty secure BGP (psBGP)

被引:88
作者
van Oorschot, P. C. [1 ]
Wan, Tao [1 ]
Kranakis, Evangelos [1 ]
机构
[1] Carleton Univ, Ottawa, ON K1S 5B6, Canada
关键词
security; reliability; standardization BGP; trust; interdomain routing; secure routing protocols; authentication; certificates; public-key infrastructure;
D O I
10.1145/1266977.1266980
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 [计算机科学与技术];
摘要
It is well known that the Border Gateway Protocol (BGP), the IETF standard interdomain routing protocol, is vulnerable to a variety of attacks, and that a single misconfigured or malicious BGP speaker could result in large-scale service disruption. In this paper, we present Pretty Secure BGP (psBGP)-a proposal for securing BGP, including an architectural overview, design details for significant aspects, and preliminary security and operational analysis. psBGP differs from other security proposals (e. g., S-BGP and soBGP) in that it makes use of a single-level PKI for AS number authentication, a decentralized trust model for verifying the propriety of IP prefix origin, and a rating-based stepwise approach for AS PATH (integrity) verification. psBGP trades off the strong security guarantees of S-BGP for presumed-simpler operation, e. g., using a PKI with a simple structure, with a small number of certificate types, and of manageable size. psBGP is designed to successfully defend against various (nonmalicious and malicious) threats from uncoordinated BGP speakers, and to be incrementally deployed with incremental benefits.
引用
收藏
页数:41
相关论文
共 56 条
[1]
ADAMS C, 2003, UNDERSTANDING PUBLIC
[2]
[Anonymous], 2003, P 10 ACM C COMPUTER
[3]
[Anonymous], 2401 IETF RFC
[4]
[Anonymous], 7 IFIP TC 6 TC 11 C
[5]
[Anonymous], 2006, The Internet Protocol Journal
[6]
BARBIR A, 2004, IN PRESS GENERIC THR
[7]
BELLOVIN S, 2004, 20 ANN COMP SEC APPL
[8]
BELLOVIN S, 2003, UNPUB USING LINK CUT
[9]
BELLOVIN S, 2005, DHS SEC ROUT WORKSH
[10]
Bellovin S. M., 1989, Computer Communication Review, V19, P32, DOI 10.1145/378444.378449