Secure Border Gateway Protocol (S-BGP)

被引:289
作者
Kent, S [1 ]
Lynn, C [1 ]
Seo, K [1 ]
机构
[1] BBN Technol, Cambridge, MA 02138 USA
关键词
denial of service; digital signatures; public-key cryptography; routing; security;
D O I
10.1109/49.839934
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
The Border Gateway Protocol (BGP), which is used to distribute routing information between autonomous systems (ASes), is a critical component of the Internet's routing infrastructure. It is highly vulnerable to a variety of malicious attacks, due to the lack of a secure means of verifying the authenticity and legitimacy of BGP control traffic. This paper describes a secure, scalable, deployable architecture (S-BGP) for an authorization and authentication system that addresses most of the security problems associated with BGP. The paper discusses the vulnerabilities and security requirements associated with BGP, describes the S-BGP countermeasures, and explains how they address these vulnerabilities and requirements. In addition, this paper provides a comparison of this architecture to other approaches that have been proposed, analyzes the performance implications of the proposed countermeasures, and addresses operational issues.
引用
收藏
页码:582 / 592
页数:11
相关论文
共 21 条
[1]  
ALAETTINOGLU C, 1998, 2280 RFC
[2]  
[Anonymous], 1998, 2385 RFC
[3]  
[Anonymous], 1995, 1771 RFC
[4]  
[Anonymous], 1998, 2406 RFC
[5]  
BATES T, 1998, 2283 RFC
[6]  
BATES T, NANOG 12
[7]  
*BBN, 1997, 8217 BBN
[8]  
Chandra R., 1996, RFC 1997
[9]  
Eastlake Donald E., 1997, RFC 2065
[10]  
Glenn R., 1998, 2410 RFC