SD-BROV: An Enhanced BGP Hijacking Protection with Route Validation in Software-Defined eXchange

SD-BROV: An Enhanced BGP Hijacking Protection with Route Validation in Software-Defined eXchange
复制标题

SD-BROV:软件定义的 eXchange 中具有路由验证的增强型 BGP 劫持保护

DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
3.4
通讯作者:
T. Ling
T. Ling
中科院分区:
--
文献类型:
--
作者:
Pang;A. C. Risdianto;Meng Hui Choi;Satis Kumar Permal;T. Ling

文献摘要

被引文献

相似文献

在全球网络中,边界网关协议BGP (Border Gateway Protocol)被广泛用于交换路由信息。虽然BGP最初的设计并没有把重点放在防止故意或意外的路由中断错误的安全保护上,但BGP的一个基本漏洞是在宣布网络层可达性的验证权威方面缺乏保险。因此,一种称为资源公钥基础设施(Resource Public Key Infrastructure, RPKI)的分布式存储库系统被用来缓解这个问题。然而,这样的验证需要自治系统(Autonomous System, AS)的进一步部署步骤,并且可能会导致遗留网络基础设施中的性能和兼容性问题。然而,随着近年来网络创新的进展,一些传统网络正计划采用软件定义网络(SDN)技术进行重组,以获得更多的利益。互联网交换点(Internet eXchange Point, IXP)通过使用SDN,可以采用软件化的控制方式,增强其管理能力,作为一个软件定义交换(software defined eXchange, SDX)中心,自适应地处理大量的广告。为了利用SDN方法增强IXP的路由安全性,本文提出了一种替代的SDX开发方案SD-BROV。SD-BROV是一种基于SDX的BGP路由起源验证机制,通过RPKI验证建立灵活的路由交换场景。内置在SDN控制器中的验证应用程序能够调查接收到的路由信息。它旨在支持混合SDN环境,帮助非SDN BGP邻居获得可信路由,并在过渡中丢弃可疑路由。为了在仿真环境中验证所提出的想法,在研究和教育网络(RENs)上运行的SDN测试平台上部署了概念验证开发。在BGP劫持实验中,实验结果表明,所开发的SD-BROV能够检测并阻止攻击者重定向的合法流量,为BGP路由器的安全转发提供了途径。
In global networks, Border Gateway Protocol (BGP) is widely used in exchanging routing information. While the original design of BGP did not focus on security protection against deliberate or accidental errors regarding to routing disruption, one of fundamental vulnerabilities in BGP is a lack of insurance in validating authority for announcing network layer reachability. Therefore, a distributed repository system known as Resource Public Key Infrastructure (RPKI) has been utilized to mitigate this issue. However, such a validation requires further deployment steps for Autonomous System (AS), and it might cause performance and compatibility problems in legacy network infrastructure. Nevertheless, with recent advancements in network innovation, some traditional networks are planning to be restructured with Software-Defined Networking (SDN) technology for gaining more benefits. By using SDN, Internet eXchange Point (IXP) is able to enhance its capability of management by applying softwarized control methods, acting as a Software-Defined eXchange (SDX) center to handle numerous advertisement adaptively. To use the SDN method to strengthen routing security of IXP, this paper proposed an alternative SDX development, SD-BROV, an SDX-based BGP Route Origin Validation mechanism that establishes a flexible route exchange scenario with RPKI validation. The validating application built in the SDN controller is capable of investigating received routing information. It aims to support hybrid SDN environments and help non-SDN BGP neighbors to get trusted routes and drop suspicious ones in transition. To verify proposed idea with emulated environment, the proof-of-concept development is deployed on an SDN testbed running over Research and Education Networks (RENs). During BGP hijacking experiment, the results show that developed SD-BROV is able to detect and stop legitimate traffic to be redirected by attacker, making approach to secure traffic forwarding on BGP routers.