Netinfo Security ›› 2015, Vol. 15 ›› Issue (11): 33-39.doi: 10.3969/j.issn.1671-1122.2015.11.006

Previous Articles     Next Articles

Research on the Evaluation Method of AS-IP Declaring Relationship Authenticity

HU Zhao-ming, LIU Lei, SHANG Bo-wen, ZHU Pei-dong   

  1. School of Computer, National University of Defense Technology, Changsha Hunan 410073, China
  • Received:2015-06-06 Online:2015-11-25 Published:2015-11-20

Abstract:

In BGP network, if an autonomous system (AS) declares an IP address prefix that not belongs to it, and then the network prefix hijack occurs. There are two reasons make prefix hijack difficult to detect: 1) Prefix hijacking will be find by the hijacked AS when and only when the IP address prefix that was hijacked was transmitted to its domain. 2) Because BGP lacks security mechanism to verify the IP address declarer have this IP address, other ASes cannot confirm the prefix hijacking even if they have got the hijacked routes. This paper presents an AS-IP declaring relationship authenticity evaluation method based on spatial consistency and temporal stability, which builds a matrix of declaring relationship according to the history routing tables, calculates a stability degree of this matrix to judge the authenticity of the declaring relationship, and generates an AS-IP matching relation knowledge base. This paper analyses and detects the routing data of RouteViews and domestic operators, and the experiments show that this method can judge the authenticity of the declaring relationship, generate a AS-IP matching relation knowledge base, and detect the prefix hijacking effectively.

Key words: inter-domain routing, declaring relationship, stability, prefix hijacking

CLC Number: