通信学报 ›› 2023, Vol. 44 ›› Issue (6): 47-56.doi: 10.11959/j.issn.1000-436x.2023114

• 学术论文 • 上一篇    下一篇

基于信誉的域间路由选择机制的研究与实现

赵仕祺, 黄小红, 钟志港   

  1. 北京邮电大学计算机学院,北京 100876
  • 修回日期:2023-06-05 出版日期:2023-06-25 发布日期:2023-06-01
  • 作者简介:赵仕祺(1992- ),男,河南南阳人,北京邮电大学博士生,主要研究方向为域间路由异常检测、事件源定位等
    黄小红(1978- ),女,广东广州人,博士,北京邮电大学副教授,主要研究方向为互联网体系结构、网络管理与测量、网络安全等
    钟志港(1996– ),男,甘肃兰州人,北京邮电大学硕士生,主要研究方向为域间路由安全
  • 基金资助:
    国家重点研发计划基金资助项目(2018YFB1800404)

Research and implementation of reputation-based inter-domain routing selection mechanism

Shiqi ZHAO, Xiaohong HUANG, Zhigang ZHONG   

  1. School of Computer Science, Beijing University of Posts and Telecommunications, Beijing 100876, China
  • Revised:2023-06-05 Online:2023-06-25 Published:2023-06-01
  • Supported by:
    The National Key Research and Development Program of China(2018YFB1800404)

摘要:

为了解决边界网关协议(BGP)缺乏对路由更新消息验证的问题,提出一种由信誉评估机制和基于信誉的BGP路由选择算法两部分组成的域间路由选择机制。信誉评估机制采用分布式自治系统(AS)联盟架构,详细划分节点路由行为,以服务域和观测权重为指标量化节点行为带来的影响,通过设计反馈机制让信誉不仅能反映节点善恶,还能反映节点对恶意攻击的抵抗能力;基于信誉的 BGP 路由选择算法在现有路由选择算法中加入一条“安全”策略:过滤包含低信誉节点的路由,并从高信誉的路由中选择最佳路由。实验结果表明,所提机制不仅抑制非法路由传播,还避开易受污染的路径,相比于现有的信誉评估机制更适用于域间路由系统,提供更加安全的域间路由环境。

关键词: 边界网关协议, 信誉机制, 路由选择机制, 网络安全

Abstract:

To solve the problem of lack of validation for exchanging messages in BGP, a inter-domain routing mechanism, which consisted of a reputation evaluation mechanism and a reputation-based BGP optimal routing algorithm, was proposed.The reputation evaluation mechanism used a distributed autonomous system (AS) alliance architecture, which divided node routing behavior in detail.The service domain and observation weight were used as indicators to quantify the impact of node behavior.By designing a feedback mechanism, the reputation value not only reflected the good and bad of nodes, but also reflected the node’s resistance to malicious attacks.The reputation-based BGP routing selection algorithm adds a “security” policy to the existing routing selection algorithm by filtering routes containing low-reputation nodes and selecting the best route among high reputation routes.The experimental results show that the proposed mechanism outperform most existing reputation mechanisms by avoiding routes with vulnerable nodes and restraining the propagation of illegal routes, thereby providing a more secure inter-domain routing environment.

Key words: border gateway protocol, reputation mechanism, routing selection mechanism, network security

中图分类号: 

No Suggested Reading articles found!