Co-Monitor:检测前缀劫持的协作监测机制
DOI:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

Supported by the National Natural Science Foundation of China Grant Nos.60873214, 60433040 (国家自然科学基金); the National High-Tech Research and Development Plan of China under Grant Nos.2006AA01Z213, 2006AA01Z332 (国家高技术研究发展计划(863)); the Research Foundation for Ph.D. Candidates of National University of Defense Technology of China under Grant No.B070603 (国防科学技术大学博士研究生创新资助)


Co-Monitor: Collaborative Monitoring Mechanism for Detecting Prefix Hijacks
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    在如今的互联网中,网络管理员要想及时地发现前缀劫持事件非常困难.考虑到互联网域间路由系统中存在的自治特性,提出了在多个自治系统之间协作监测前缀的思想,并由此设计了一个实时检测前缀劫持的新方法——Co-Monitor机制.在Co-Monitor中,每个参与者与其他参与者交换自定义的前缀-源自治系统映射信息,同时,利用所学到的前缀-源自治系统映射信息实时地监测本地BGP(border gateway protocol)路由更新.一旦某个参与者发现了不一致就立刻通知相关的参与者,从而可帮助参与者及时、有效地发现前缀劫持.给出了Co-Monitor机制的详细设计,评估了该机制的检测能力,并讨论了几个相关的问题.实验结果表明,只需精心选择60个参与者,就可确保Co-Monitor系统检测前缀劫持的漏检率和误检率都为0%.

    Abstract:

    In today’s Internet, it is very difficult for network operators to discover prefix hijacks in time. Considering the autonomous characteristic of the Internet inter-domain routing system, this paper provides the idea of collaborative monitoring among multiple Autonomous Systems (ASes). This paper also examines the design of a new method, named Co-Monitor that detects prefix hijacks in real-time. In Co-Monitor, every participant AS exchanges self-defined prefix-to-origin mapping information with the others, and they monitor local BGP (border gateway protocol) updates respectively. Once some participant discovers that the origin of information of a BGP route is inconsistent with the learned prefix-to-origin mapping information, it notifies relative participants immediately; thereby, Co-Monitor can help participants detect prefix hijacks quickly and effectively. This paper presents the detailed design of Co-Monitor, evaluates its detecting capabilities, and also discusses several related problems. The experimental results show that Co-Monitor, with only selected 60 participants, is accurate with 0% false negative ratio and 0% false positive ratio.

    参考文献
    相似文献
    引证文献
引用本文

刘欣,朱培栋,彭宇行. Co-Monitor:检测前缀劫持的协作监测机制.软件学报,2010,21(10):2584-2598

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2008-08-25
  • 最后修改日期:2009-05-05
  • 录用日期:
  • 在线发布日期:
  • 出版日期:
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号