BGP Communities: Even more Worms in the Routing Can

BGP Communities: Even more Worms in the Routing Can
复制标题

BGP 社区:路由中存在更多蠕虫

DOI:
10.1145/3278532.3278557
复制
发表时间:
2018
期刊:
Proceedings of the Internet Measurement Conference 2018
影响因子:
--
通讯作者:
R. Bush
R. Bush
中科院分区:
--
文献类型:
--
作者:
Florian Streibelt;F. Lichtblau;Robert Beverly;A. Feldmann;C. Pelsser;Georgios Smaragdakis;R. Bush

文献摘要

被引文献

相似文献

BGP社区是运营商广泛用于管理策略、减轻攻击和设计流量的机制;例如,以丢弃不需要的业务、过滤通知、调整本地偏好、以及预置路径来影响对等体选择。不幸的是,我们发现,BGP社区可以利用远程方影响路由的意想不到的方式。我们暴露的基于BGP社区的漏洞是由复杂的策略,容易出错的配置,社区缺乏加密完整性和真实性以及社区传播的广泛程度相结合而实现的。部分由于其定义不清的语义,BGP社区通常传播远超过单个路由跳,即使其预期范围通常限于附近的AS。事实上,我们发现有14%的中转AS转发了BGP社区。鉴于过境AS的丰富互连性,这意味着社区有效地在全球传播。因此,即使没有前缀劫持,远程攻击者也可以使用BGP社区来触发远程黑洞、引导流量和操纵路由。我们通过我们在实验室和野外测试和测量的场景来突出这些攻击的示例。虽然我们建议可以做些什么来减轻这种不良影响,但是否采纳这些建议取决于互联网运营界。
BGP communities are a mechanism widely used by operators to manage policy, mitigate attacks, and engineer traffic; e.g., to drop unwanted traffic, filter announcements, adjust local preference, and prepend paths to influence peer selection. Unfortunately, we show that BGP communities can be exploited by remote parties to influence routing in unintended ways. The BGP community-based vulnerabilities we expose are enabled by a combination of complex policies, error-prone configurations, a lack of cryptographic integrity and authenticity over communities, and the wide extent of community propagation. Due in part to their ill-defined semantics, BGP communities are often propagated far further than a single routing hop, even though their intended scope is typically limited to nearby ASes. Indeed, we find 14% of transit ASes forward received BGP communities onward. Given the rich inter-connectivity of transit ASes, this means that communities effectively propagate globally. As a consequence, remote adversaries can use BGP communities to trigger remote blackholing, steer traffic, and manipulate routes even without prefix hijacking. We highlight examples of these attacks via scenarios that we tested and measured both in the lab as well as in the wild. While we suggest what can be done to mitigate such ill effects, it is up to the Internet operations community whether to take up the suggestions.