计算机工程与科学
計算機工程與科學
계산궤공정여과학
COMPUTER ENGINEERING & SCIENCE
2010年
2期
60-62,138
,共4页
马俊%蔡开裕%曹华阳%刘欣
馬俊%蔡開裕%曹華暘%劉訢
마준%채개유%조화양%류흔
BGP%域间路由%多层次%安全监测
BGP%域間路由%多層次%安全鑑測
BGP%역간로유%다층차%안전감측
BGP%inter-domain routing%mutil-level%security monitor
基于边界网关协议(BGP)的域间路由系统已经成为Internet的核心路由设施,但由于BGP本身缺乏安全机制,很容易受到各种人为配置错误或者恶意攻击的影响.我们开发的域间路由监测系统可以从4个层次实现对域间路由的安全监测,分别是Internet、国家网络、特定ISP和特定路由.本文详细介绍了多层次域间路由安全监测系统的组成结构、软件结构、设计思想、实现技术和测试结果.
基于邊界網關協議(BGP)的域間路由繫統已經成為Internet的覈心路由設施,但由于BGP本身缺乏安全機製,很容易受到各種人為配置錯誤或者噁意攻擊的影響.我們開髮的域間路由鑑測繫統可以從4箇層次實現對域間路由的安全鑑測,分彆是Internet、國傢網絡、特定ISP和特定路由.本文詳細介紹瞭多層次域間路由安全鑑測繫統的組成結構、軟件結構、設計思想、實現技術和測試結果.
기우변계망관협의(BGP)적역간로유계통이경성위Internet적핵심로유설시,단유우BGP본신결핍안전궤제,흔용역수도각충인위배치착오혹자악의공격적영향.아문개발적역간로유감측계통가이종4개층차실현대역간로유적안전감측,분별시Internet、국가망락、특정ISP화특정로유.본문상세개소료다층차역간로유안전감측계통적조성결구、연건결구、설계사상、실현기술화측시결과.
As we all know, the inter-domain routing systems, based on BGP (Boarder Gateway Protocol, BGP), has become the core routing facilities of the Internet. However, due to their lack of the BGP security mechanism, BGP is vulnerable to all kinds of human configuration errors or malicious attacks. We develop a multi-level inter-domain routing security monitoring system, and it can achieve four levels of domain routing, including the Internet, national network, a particular ISP and a specific route. This paper describes the system's composition structure, software structure, design, implementation technology and the achieved results.