Safeguarding Data Delivery by Decoupling Path Propagation and Adoption

Mingui Zhang, B. Liu, Beichuan Zhang
{"title":"Safeguarding Data Delivery by Decoupling Path Propagation and Adoption","authors":"Mingui Zhang, B. Liu, Beichuan Zhang","doi":"10.1109/INFCOM.2010.5462200","DOIUrl":null,"url":null,"abstract":"False routing announcements are a serious security problem, which can lead to widespread service disruptions in the Internet. A number of detection systems have been proposed and implemented recently, however, it takes time to detect attacks, notify operators, and stop false announcements. Thus detection systems should be complemented by a mitigation scheme that can protect data delivery before the attack is resolved. We propose such a mitigation scheme, QBGP, which decouples the propagation of a path and the adoption of a path for data forwarding. QBGP does not use suspicious paths to forward data traffic, but still propagates them in the routing system to facilitate attack detection. It can protect data delivery from routing announcements of false sub-prefixes, false origins, false nodes and false links. QBGP incurs overhead only when there are suspicious paths, which happen infrequently in real BGP traces. Results from large scale simulations and BGP trace analysis show that QBGP is light-weight yet effective, and it converges faster and incurs less overhead than Pretty Good BGP.","PeriodicalId":259639,"journal":{"name":"2010 Proceedings IEEE INFOCOM","volume":"29 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-03-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 Proceedings IEEE INFOCOM","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INFCOM.2010.5462200","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

False routing announcements are a serious security problem, which can lead to widespread service disruptions in the Internet. A number of detection systems have been proposed and implemented recently, however, it takes time to detect attacks, notify operators, and stop false announcements. Thus detection systems should be complemented by a mitigation scheme that can protect data delivery before the attack is resolved. We propose such a mitigation scheme, QBGP, which decouples the propagation of a path and the adoption of a path for data forwarding. QBGP does not use suspicious paths to forward data traffic, but still propagates them in the routing system to facilitate attack detection. It can protect data delivery from routing announcements of false sub-prefixes, false origins, false nodes and false links. QBGP incurs overhead only when there are suspicious paths, which happen infrequently in real BGP traces. Results from large scale simulations and BGP trace analysis show that QBGP is light-weight yet effective, and it converges faster and incurs less overhead than Pretty Good BGP.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
通过解耦路径传播和采用来保护数据传递
错误路由通知是一个严重的安全问题,它可能导致互联网上广泛的服务中断。最近已经提出并实施了许多检测系统,然而,检测攻击、通知运营商和停止虚假通知需要时间。因此,检测系统应辅以缓解方案,在攻击解决之前保护数据传输。我们提出了这样一种缓解方案,QBGP,它将路径的传播和采用路径进行数据转发解耦。QBGP不使用可疑路径转发数据流量,而是在路由系统中进行传播,方便检测攻击。它可以保护数据传输免受虚假子前缀、虚假起源、虚假节点和虚假链接的路由通知。QBGP只在有可疑路径的情况下才会产生开销,而在实际的BGP路径中,这种情况很少发生。大规模仿真和BGP跟踪分析结果表明,与Pretty Good BGP相比,QBGP具有轻量级、高效、收敛速度快、开销小等优点。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Truthful Least-Priced-Path Routing in Opportunistic Spectrum Access Networks Overcoming Failures: Fault-tolerance and Logical Centralization in Clean-Slate Network Management Improving QoS in BitTorrent-like VoD Systems Lightweight Mutual Authentication and Ownership Transfer for RFID Systems Overhearing-aware Joint Routing and Rate Selection in Multi-hop Multi-rate UWB-based WPANs
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1