The Juice Is Worth the Squeeze: Analysis of Autonomous System Provider Authorization in Partial Deployment
The Juice Is Worth the Squeeze: Analysis of Autonomous System Provider Authorization in Partial Deployment
复制标题
果汁值得榨取:部分部署中自治系统提供商授权分析
DOI:
10.1109/ojcoms.2022.3233833
复制
发表时间:
2023
影响因子:
7.9
通讯作者:
Yanai Naoto
中科院分区:
文献类型:
--
作者:
Umeda Naoki;Kimura Taiji;Yanai Naoto
BGP, the de-facto standard protocol for exchanging routes on a network-wide basis called AS employs invalid routes. Recently, a data object called Autonomous System Provider Authorization (ASPA) was proposed as a new specification for verifying PATH information in BGP security. In this paper, we shed light on the effectiveness of ASPAs in a partial deployment alongside the conventional BGP through experiments based on a real AS topology. To this end, we also present a novel simulation tool, LOTUS, for BGP route exchange, including ASPAs. We then evaluate deployments of ASPAs and their verification with LOTUS for two cases on network topology in Japan: the case in deployment from ASes whose number of connections with other ASes is large, i.e., deployment from top ASes, and the case in deployment from ASes at the end of the network topology, i.e., deployment from leaf-node ASes. As a result, we confirm that the number of victim ASes decreases in the former case, while ASPAs provide no advantage in the latter case. Notably, the number of victim ASes decreases by about 96% on average by deploying the verification with ASPAs in the top-eight ASes. Based on these results, we further conduct extensive experiments in the deployment from the top ASes, whereby ASes outside the network topology advertise malicious routes to the victim ASes. We also discuss a case whereby an adversary tries to leverage ASPAs. Our promising results show that the adversary will no longer obtain an advantage even by leveraging ASPAs.
登录
查看更多内容
DOI:
10.1145/3548606.3563523
发表时间:
2022
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
Haya Schulmann;Niklas Vogel;M. Waidner
通讯作者:
M. Waidner
DOI:
10.1007/978-3-030-29959-0_6
发表时间:
2019
期刊:
--
影响因子:
--
作者:
Loïc Miller;C. Pelsser
通讯作者:
C. Pelsser
DOI:
10.17487/rfc7908
发表时间:
2016
期刊:
RFC
影响因子:
--
作者:
C. Maurer
通讯作者:
C. Maurer
影响因子:
3.4
作者:
Pang;A. C. Risdianto;Meng Hui Choi;Satis Kumar Permal;T. Ling
通讯作者:
T. Ling
DOI:
10.1145/3319535.3363197
发表时间:
2019
期刊:
2019 ACM SIGSAC Conference on Computer and Communications Security CCS.
影响因子:
--
作者:
Birge-Lee, Henry;Wang, Liang;Rexford, Jennifer;Mittal, Prateek
通讯作者:
Mittal, Prateek