by
Christopher Kruegel
,
Darren Mutz
,
William Robertson
,
Fredrik Valeur
In Proceedings of the 6th Symposium on Recent Advances in Intrusion Detection (RAID
Add To MetaCart
Abstract:
The Border Gateway Protocol (BGP) is a fundamental component of the current Internet infrastructure. Due to the inherent trust relationship between peers, control of a BGP router could enable an attacker to redirect trac allowing man-in-the-middle attacks or to launch a large-scale denial of service. It is known that BGP has weaknesses that are fundamental to the protocol design. Many solutions to these weaknesses have been proposed, but most require resource intensive cryptographic operations and modi cations to the existing protocol and router software. For this reason, none of them have been widely adopted. However, the threat necessitates an eective, immediate solution.
Citations
|
786
|
On power-law relationships of the Internet topology
– Faloutsos, Faloutsos, et al.
- 1999
|
|
490
|
OSPF version 2
– Moy
- 1994
|
|
276
|
A Border Gateway
– Rekhter, Li
- 1995
|
|
261
|
On inferring autonomous system relationships in the Internet
– Gao
|
|
245
|
Characterizing the Internet hierarchy from multiple vantage points
– Subramanian, Agarwal, et al.
- 2002
|
|
225
|
Internet Routing Instability
– Labovitz, Malan, et al.
|
|
175
|
A quantitative comparison of graph-based models for internet topology
– Zegura, Calvert, et al.
- 1997
|
|
113
|
Experimental Study of Internet Stability and Wide-Area Backbone Failures
– Labovitz, Ahuja, et al.
- 1999
|
|
101
|
An analysis of Internet inter-domain topology and route stability
– Govindan, Reddy
- 1997
|
|
85
|
Working around BGP: An incremental approach to improving security and accuracy of interdomain routing
– Goodell, Aiello, et al.
- 2003
|
|
71
|
Secure Border Gateway Protocol (Secure-BGP
– Kent, Lynn, et al.
- 2000
|
|
71
|
RIP Version 2
– Malkin
- 1998
|
|
68
|
An efficient message authentication scheme for link state routing
– Cheung
- 1997
|
|
62
|
Garcia Luna~Acever, "Securing DistanceVector Routing Protoco~," Proc. Symp. Nehvork mid Dirt Sys. Security. Los Alomibr
– Smith, J
- 1997
|
|
45
|
Digital signature protection of OSPF routing protocol In Internet society symposium on network and distributed system security
– Murphy
- 1996
|
|
28
|
Design and implementation of a scalable intrusion detection system for the protection of network infrastructure
– Jou, Gong, et al.
- 2000
|
|
26
|
An Analysis
– Zhao, Pei, et al.
- 2001
|
|
17
|
Statistical Anomaly Detection for Link-State Routing Protocols
– Qu, Vetter, et al.
- 1998
|
|
17
|
Reducing the Cost of Security in Link State Routing
– Hauser, Przygienda, et al.
- 1997
|
|
9
|
Sensor-Based Intrusion Detection for Intra-Domain Distance-Vector Routing
– Mittal, Vigna
- 2002
|
|
4
|
Border Gateway Protocol Security Analysis
– Murphy
- 2001
|
|
3
|
An Attack Tree for the Border Gateway Protocol
– Convey, Cook, et al.
- 2002
|
|
3
|
PCH RouteViews archive,” http://www.pch.net/documents/data/routing-tables
– McCreary, Woodcook
|
|
2
|
Cable and Wireless Routing Instability
– Farrar
|
|
1
|
Understanding BGP Miscon
– Mahajan, Wetherall, et al.
- 2002
|