The Juice Is Worth the Squeeze: Analysis of Autonomous System Provider Authorization in Partial Deployment

The Juice Is Worth the Squeeze: Analysis of Autonomous System Provider Authorization in Partial Deployment
复制标题

果汁值得榨取:部分部署中自治系统提供商授权分析

DOI:
10.1109/ojcoms.2022.3233833
复制
发表时间:
2023
影响因子:
7.9
通讯作者:
Yanai Naoto
Yanai Naoto
中科院分区:
--
文献类型:
--
作者:
Umeda Naoki;Kimura Taiji;Yanai Naoto

文献摘要

参考文献

相似文献

BGP是在网络范围内交换路由的事实标准协议,称为AS,它使用无效路由。最近,一个名为自治系统提供者授权(ASPA)的数据对象被提出作为BGP安全中验证路径信息的新规范。在本文中,我们揭示了ASPA的有效性,在部分部署的传统BGP通过实验的基础上,一个真实的AS拓扑结构。为此,我们还提出了一种新的模拟工具,LOTUS,BGP路由交换,包括ASPA。然后,我们评估部署的ASPA和他们的验证与LOTUS的两种情况下,在日本的网络拓扑结构:部署的情况下,从AS的连接数量与其他AS是大的,即,从顶部AS部署的情况,以及从网络拓扑末端的AS部署的情况,即,从叶节点AS部署。因此,我们确认,在前一种情况下,受害者AS的数量减少,而ASPA在后一种情况下没有提供任何优势。值得注意的是,通过在前八个AS中部署ASPA的验证,受害AS的数量平均减少约96%。基于这些结果,我们进一步进行了广泛的实验,在部署从顶部AS,其中AS网络拓扑结构之外的广告恶意路由到受害者AS。我们还讨论了对手试图利用ASPA的情况。我们有希望的结果表明,对手将不再获得优势,即使利用ASPA。
BGP, the de-facto standard protocol for exchanging routes on a network-wide basis called AS employs invalid routes. Recently, a data object called Autonomous System Provider Authorization (ASPA) was proposed as a new specification for verifying PATH information in BGP security. In this paper, we shed light on the effectiveness of ASPAs in a partial deployment alongside the conventional BGP through experiments based on a real AS topology. To this end, we also present a novel simulation tool, LOTUS, for BGP route exchange, including ASPAs. We then evaluate deployments of ASPAs and their verification with LOTUS for two cases on network topology in Japan: the case in deployment from ASes whose number of connections with other ASes is large, i.e., deployment from top ASes, and the case in deployment from ASes at the end of the network topology, i.e., deployment from leaf-node ASes. As a result, we confirm that the number of victim ASes decreases in the former case, while ASPAs provide no advantage in the latter case. Notably, the number of victim ASes decreases by about 96% on average by deploying the verification with ASPAs in the top-eight ASes. Based on these results, we further conduct extensive experiments in the deployment from the top ASes, whereby ASes outside the network topology advertise malicious routes to the victim ASes. We also discuss a case whereby an adversary tries to leverage ASPAs. Our promising results show that the adversary will no longer obtain an advantage even by leveraging ASPAs.
海报:深入了解 RPKI 验证的全球部署
DOI: 10.1145/3548606.3563523
发表时间: 2022
期刊: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Haya Schulmann;Niklas Vogel;M. Waidner
通讯作者: M. Waidner
使用 BGP 黑洞攻击的分类
DOI: 10.1007/978-3-030-29959-0_6
发表时间: 2019
期刊: --
影响因子: --
作者:
Loïc Miller;C. Pelsser
通讯作者: C. Pelsser
DOI: 10.17487/rfc7908
发表时间: 2016
期刊: RFC
影响因子: --
作者:
C. Maurer
通讯作者: C. Maurer
SD-BROV:软件定义的 eXchange 中具有路由验证的增强型 BGP 劫持保护
DOI: --
发表时间: 2021
期刊: Future Internet
影响因子: 3.4
作者:
Pang;A. C. Risdianto;Meng Hui Choi;Satis Kumar Permal;T. Ling
通讯作者: T. Ling
SICO:通过操纵 BGP 社区进行外科手术式拦截攻击
DOI: 10.1145/3319535.3363197
发表时间: 2019
期刊: 2019 ACM SIGSAC Conference on Computer and Communications Security CCS.
影响因子: --
作者:
Birge-Lee, Henry;Wang, Liang;Rexford, Jennifer;Mittal, Prateek
通讯作者: Mittal, Prateek