首页> 外文会议>2011 13th Asia-Pacific Network Operations and Management Symposium >IP prefix hijacking detection using the collection of as characteristics
【24h】

IP prefix hijacking detection using the collection of as characteristics

机译:使用as特征的集合进行IP前缀劫持检测

获取原文

摘要

IP prefix hijacking is a well-known security threat that corrupts Internet routing tables and has some common characteristics such as MOAS conflicts and invalid routes in BGP messages. We propose a simple but effective IP prefix hijacking detection method which is based on reachability monitoring. Network reachability means a characteristic that a packet must reach the destination network although the network path is changed due to routing instability. However, when IP prefix hijacking occurs, the traffic sent to victim network does not reach the intended destination but is delivered to attacker network. By identifying the characteristics of the destination network such as network fingerprints, we can know whether the traffic reach the correct destination. In this paper, we present the method of collecting network fingerprints for verifying destination reachability and also propose an IP prefix hijacking detection method using the collected fingerprints. The IP prefix hijacking detection method based on network reachability is effective and useful, which uses a simple active probing and denotes a present network condition.
机译:IP前缀劫持是一种众所周知的安全威胁,它会破坏Internet路由表并具有一些常见的特征,例如MOAS冲突和BGP消息中的无效路由。我们提出了一种基于可达性监视的简单有效的IP前缀劫持检测方法。网络可达性是指尽管由于路由不稳定而改变了网络路径,但数据包仍必须到达目标网络的特征。但是,当发生IP前缀劫持时,发送到受害网络的流量不会到达预期的目的地,而是传递到攻击者网络。通过识别目标网络的特征(例如网络指纹),我们可以知道流量是否到达正确的目标。在本文中,我们提出了一种收集网络指纹以验证目的地可达性的方法,并提出了一种使用收集到的指纹进行IP前缀劫持检测的方法。基于网络可达性的IP前缀劫持检测方法是有效且有用的,它使用简单的主动探测并表示当前的网络状况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号