Path stability in partially deployed secure BGP routing

被引:1
|
作者
Yang, Yan [1 ]
Shi, Xingang [2 ,3 ]
Ma, Qiang [1 ]
Li, Yahui [4 ]
Yin, Xia [1 ,3 ]
Wang, Zhiliang [2 ,3 ]
机构
[1] Tsinghua Univ, Dept Comp Sci & Technol, Beijing, Peoples R China
[2] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing, Peoples R China
[3] Beijing Natl Res Ctr Informat Sci & Technol BNRIS, Beijing, Peoples R China
[4] Beijing Jiaotong Univ, Sch Software Engn, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
Routing; Secure BGP; Partial Deployment; Stability;
D O I
10.1016/j.comnet.2022.108762
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Border Gateway Protocol (BGP), as the current de-facto routing protocol connecting various cooperating domains on the Internet, did not consider security when it was originally designed. With the expansion of the Internet, security is increasingly valued and many BGP enhancement mechanisms are proposed and experimented. Some of them like BGPsec have been standardized and promoted by the IETF. However, the deployment of these inter-domain secure routing mechanisms is subject to many economic and political restrictions. Consequently, there will be a long period of partial deployment, during which instability of BGP can be observed. Specifically, when some networks start deploying secure BGP mechanisms, they may be involved in some temporary or persistent route oscillations. In this paper, we systematically study the stability problem induced by partially deployed secure BGP mechanisms. We analyze the characteristics of topology and routing strategies when BGP oscillations will be introduced. In particular, we propose dispute chain, a derived structure of dispute wheel proposed in Griffin et al. (2002), to formally analyze this problem. Based on dispute chain, we analyze how different security adoption strategies can cause BGP oscillations under the general Gao-Rexford model. Our analysis shows that, even in a situation when there is no dispute wheel, dispute chains may widely appear, indicating that BGP oscillation problems will be introduced when security mechanisms are casually deployed, affecting the security and quality of inter-domain communications. To avoid possible oscillations, we also propose some deployment guidelines from different perspectives of the operator and the Internet, so that a wider deployment of security mechanisms will not blindly disrupt the Internet.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] SPV: Secure Path Vector routing for securing BGP
    Hu, YC
    Perrig, A
    Sirbu, M
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2004, 34 (04) : 179 - 192
  • [2] BGP routing stability of popular destinations
    Rexford, J
    Jia, W
    Zhen, X
    Yin, Z
    [J]. IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, 2002, : 197 - 202
  • [3] On interdomain routing security and pretty secure BGP (psBGP)
    van Oorschot, P. C.
    Wan, Tao
    Kranakis, Evangelos
    [J]. ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2007, 10 (03)
  • [4] AIDR: Aggregation of BGP Routing Table with AS Path Stretch
    Wang, Yangyang
    Bi, Jun
    Wu, Jianping
    [J]. 2011 19TH IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2011,
  • [5] BGP-ELF: Enhancing BGP To Eliminate Routing Loops and Oscillations without Path Vectors
    Garica-Luna-Aceves, J. J.
    [J]. 2022 IEEE FUTURE NETWORKS WORLD FORUM, FNWF, 2022, : 197 - 202
  • [6] A Novel Algorithm for AS Path Inference Based on BGP Routing Tables
    Mu Xiao-yang
    Chen Yue-xin
    Deng Yue-hua
    Zheng Hui
    [J]. 2013 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT), 2013, : 196 - 199
  • [7] RouteChain: Towards Blockchain-based Secure and Efficient BGP Routing
    Saad, Muhammad
    Anwar, Afsah
    Ahmad, Ashar
    Alasmary, Hisham
    Yuksel, Murat
    Mohaisen, Aziz
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (ICBC), 2019, : 210 - 218
  • [8] RouteChain: Towards Blockchain-based secure and efficient BGP routing
    Saad, Muhammad
    Anwar, Afsah
    Ahmad, Ashar
    Alasmary, Hisham
    Yuksel, Murat
    Mohaisen, David
    [J]. COMPUTER NETWORKS, 2022, 217
  • [9] A secure alternate path routing in sensor networks
    Lee, Suk-Bok
    Choi, Yoon-Hwa
    [J]. COMPUTER COMMUNICATIONS, 2006, 30 (01) : 153 - 165
  • [10] Credible BGP - Extensions to BGP for Secure Networking
    Israr, Junaid
    Guennoun, Mouhcine
    Mouftah, Hussein T.
    [J]. 2009 4TH INTERNATIONAL CONFERENCE ON SYSTEMS AND NETWORKS COMMUNICATIONS (ICSNC 2009), 2009, : 212 - 216