首页> 外文会议>2012 20th IEEE International Conference on Network Protocols. >Buddyguard: A buddy system for fast and reliable detection of IP prefix anomalies
【24h】

Buddyguard: A buddy system for fast and reliable detection of IP prefix anomalies

机译:Buddyguard:一种可快速可靠地检测IP前缀异常的伙伴系统

获取原文
获取原文并翻译 | 示例

摘要

Due to operational malpractice or security attacks, an IP prefix (i.e., a block of IP addresses) can undergo many types of routing anomalies. Perhaps the most well-known of such anomalies is prefix hijacking, where an attacker hijacks traffic meant to reach the legitimate user of a prefix. Anomalies can also easily occur through route leaks, which can disrupt traffic for numerous prefixes at once. While various solutions have been proposed to detect such anomalies, these solutions are limited and susceptible to attacker countermeasures. In this paper we present Buddyguard, a new approach to detecting prefix anomalies including prefix hijacking and route leaks. Buddyguard compares the behavior of a monitored prefix with the behavior of a set of numerous buddy prefixes. The system detects anomalies when the behavior of the monitored prefix significantly diverges from that of its buddies. Our evaluation results show that Buddyguard provides fast, accurate and lightweight monitoring of IP prefix anomalies, and its introduction and use of buddy prefixes enables it to be resilient against resourceful attackers.
机译:由于操作失当或安全攻击,IP前缀(即IP地址块)可能会经历多种类型的路由异常。此类异常中最著名的也许是前缀劫持,攻击者在其中劫持了旨在到达前缀合法用户的流量。路由泄漏也很容易引起异常,从而可能一次中断大量前缀的流量。尽管已经提出了各种解决方案来检测这种异常,但是这些解决方案是有限的,并且容易受到攻击者的对策。在本文中,我们介绍了Buddyguard,这是一种检测前缀异常的新方法,包括前缀劫持和路由泄漏。 Buddyguard将受监视前缀的行为与一组众多伙伴前缀的行为进行比较。当监视的前缀的行为与其伙伴的行为明显不同时,系统会检测到异常。我们的评估结果表明,Buddyguard提供了对IP前缀异常的快速,准确和轻量级监视,并且其引入和使用伙伴前缀使它可以灵活地应对足智多谋的攻击者。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号