• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2010, Vol. 32 ›› Issue (2): 60-62.doi: 10.3969/j.issn.1007130X.2010.

• 论文 • 上一篇    下一篇

多层次域间路由安全监测系统的设计与实现

  

  1. (国防科学技术大学计算机学院,湖南 长沙 410073)
  • 收稿日期:2008-09-10 修回日期:2008-12-16 出版日期:2010-01-25 发布日期:2010-01-26
  • 通讯作者: 马俊 E-mail:fancy_421@126.com
  • 作者简介:马俊(1984),男,江西南昌人,硕士生,研究方向为路由安全;蔡开裕,副教授,研究方向为网络与通信、路由安全。

Design and Implementation of a MultiLevel InterDomain Routing Security Monitoring System

  1. (School of Computer Science,National University of Defense Technology,Changsha 410073,China)
  • Received:2008-09-10 Revised:2008-12-16 Online:2010-01-25 Published:2010-01-26

摘要:

基于边界网关协议(BGP)的域间路由系统已经成为Internet的核心路由设施,但由于BGP本身缺乏安全机制,很容易受到各种人为配置错误或者恶意攻击的影响。我们开发的域间路由监测系统可以从4个层次实现对域间路由的安全监测,分别是Internet、国家网络、特定ISP和特定路由。本文详细介绍了多层次域间路由安全监测系统的组成结构、软件结构、设计思想、实现技术和测试结果。

关键词: BGP, 域间路由, 多层次, 安全监测

Abstract:

As we all know, the interdomain routing systems, based on BGP (Boarder Gateway Protocol, BGP), has become the core routing facilities of the Internet. However, due to their lack of the BGP security mechanism, BGP is vulnerable to all kinds of human configuration errors or malicious attacks. We develop a multilevel interdomain routing security monitoring system, and it can achieve four levels of domain routing, including the Internet, national network, a particular ISP and a specific route. This paper describes the system's composition structure, software structure, design, implementation technology and the achieved results.

Key words: BGP;interdomain routing;mutillevel;security monitor

中图分类号: