Netinfo Security ›› 2017, Vol. 17 ›› Issue (7): 52-58.doi: 10.3969/j.issn.1671-1122.2017.07.008

• Orginal Article • Previous Articles     Next Articles

A Network Topology Discovery Algorithm Resistant to Routing Spoofing

Yifang ZHAO(), Dongmei ZHANG   

  1. School of Cyberspace Security, Beijing University of Post and Telecommunication, Beijing 100876, China
  • Received:2017-05-11 Online:2017-07-20 Published:2020-05-12

Abstract:

Accurate and comprehensive network topology can directly and effectively present the structure and state of the current network to network managers, so an accurate and complete network topology is an important part of network fault management, configuration management, and security management. Proactive detection based on ICMP and ARP has negative effects on the performance of network. The existing network topology discovery method based on IS-IS is difficult to ensure efficiency on describing IP network when attack based on routing protocol occurred. Then this paper proposes an algorithm for IP network topology based on IS-IS by analyzing the LSP packet, the algorithm obtains the information of network topology such as the relationship of the links between routers without making influence on network, then produce a believable, complete base network topology and request PSNP for security to avoid network topology changes caused by routing spoofing. The simulation result shows the algorithm can get a complete network topology in a routing spoofing environment which verified the feasibility of algorithm.

Key words: IS-IS protocol, topology discovery, data authenticity, IP network

CLC Number: