Analysis of Impact of Trust on Secure Border Gateway Protocol

被引:0
|
作者
Israr, Junaid [1 ]
Guennoun, Mouhcine [1 ]
Mouftah, Hussein T. [1 ]
机构
[1] Univ Ottawa, Sch Informat Technol & Engn, Ottawa, ON, Canada
关键词
S-BGP; Trust Model; Digital Signature;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Secure Border Gateway Protocol (S-BGP) mandates that upon reception of a BGP UPDATE message, an S-BGP speaker must verify nested signatures of all nodes in the traversed path; and the router should verify the Address Attestation to check if the source has the right to announce the address prefix. Due to several digital signatures required in each UPDATE, there is a high CPU overhead associated with S-BGP. In this paper, we propose a new approach that reduces the burden of validating the AS-path and the address prefix origination. We define a control layer of trusted nodes that is comprised of major Autonomous Systems (ASes) in the network. In this environment, an AS has to verify only the signatures of intermediate ASes between itself and the last trusted node in the AS-path. Similarly, the address prefix is validated only if it was not previously validated by a trusted AS. Using an original analytical model as well as a simulation model, we measured performance metrics of the new proposal. We show that even with small ratio of trusted nodes, the new scheme can significantly reduce the number of verifications required to validate the AS-path and IP prefixes and the number of public keys required by S-BGP.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Design, implementation, and performance analysis of a secure payment protocol in a payment gateway centric model
    Jesús Téllez Isaac
    Sherali Zeadally
    Computing, 2014, 96 : 587 - 611
  • [22] A formal model for checking the convergence property of border gateway protocol
    Yin, Ping
    Ma, Yinxue
    ICIC Express Letters, Part B: Applications, 2014, 5 (06): : 1753 - 1758
  • [23] Optimized MRAI Timers for Border Gateway Protocol in Large Networks
    Shukla, Shipra
    Kumar, Mahesh
    INTERNATIONAL JOURNAL OF DISTRIBUTED SYSTEMS AND TECHNOLOGIES, 2019, 10 (04) : 31 - 44
  • [24] Border Gateway Protocol (BGP) and Traceroute Data Workshop Report
    Claffy, Kc
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2012, 42 (03) : 28 - 31
  • [25] Enhancing Border Gateway Protocol Security using Public Blockchain
    Shukla, Shipra
    Gupta, Swastika
    Rai, Misha
    Bhati, Muskan
    Chaudhary, Vanshika
    14th International Conference on Advances in Computing, Control, and Telecommunication Technologies, ACT 2023, 2023, 2023-June : 2381 - 2389
  • [26] Scalable Verification of Border Gateway Protocol Configurations with an SMT Solver
    Weitz, Konstantin
    Woos, Doug
    Torlak, Emina
    Ernst, Michael D.
    Krishnamurthy, Arvind
    Tatlock, Zachary
    ACM SIGPLAN NOTICES, 2016, 51 (10) : 765 - 780
  • [27] BGP-MX: Border Gateway Protocol with Mobility Extensions
    Kaddoura, Maher
    Trent, Barry
    Ramanujan, Ranga
    Hadynski, Gregory
    2011 - MILCOM 2011 MILITARY COMMUNICATIONS CONFERENCE, 2011, : 687 - 692
  • [28] A Survey of Advanced Border Gateway Protocol Attack Detection Techniques
    Scott, Ben A.
    Johnstone, Michael N.
    Szewczyk, Patryk
    SENSORS, 2024, 24 (19)
  • [29] Multidomain SDN-Based Gateways and Border Gateway Protocol
    Alotaibi, Hamad Saud
    Gregory, Mark A.
    Li, Shuo
    JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2022, 2022
  • [30] Border gateway protocol monitoring system can be cost effective
    Chen, K.
    Hu, C.
    IET COMMUNICATIONS, 2011, 5 (15) : 2231 - 2240