Descartes BGP : A Conflict Detection and Response Framework for Inter - Domain Routing
ثبت نشده
چکیده
—We present Descartes BGP (D-BGP), a fault detection and response framework that enhances the robustness, security, and manageability of inter-domain routing. D-BGP associates a state of " agreement, " " conflict, " or " persistent conflict " with each announced address prefix. When a D-BGP router receives a routing update in which a new AS claims to be an origin of a prefix, it alerts other D-BGP routers to collaboratively verify their ownership claim and resolve the potential conflict without reference to an oracle, such as a topology database server. If a conflict is " persistent, " a black hole may have formed, pulling traffic destined to the prefix in conflict. When this happens, D-BGP logs useful diagnostic information to aid resolution by network administrators. In spite of the black hole, the D-BGP framework allows data traffic to reach critical network services located on or needed by the hosts within the prefix. We evaluate D-BGP with the Scaleable Simulation Framework NETwork (SSFNET) simulator and show that D-BGP resolves BGP faults and misconfigurations in real time, and mitigates a persistent conflict over the ownership of an IP prefix. We show that D-BGP provides path resilience quickly and with few messages. Using BGP update data obtained during an actual black hole event, we show that D-BGP's detection mechanism scales well. «au contraire de cela, même que je pensais à douter de la vérité des autres choses, il suivait très évidemment et très certainement que j'étais.» " to the contrary, in the very act of thinking about doubting the truth of other things, it very clearly and certainly followed that I existed. "-René Descartes (1596-1650), Le Discours de la Méthode, Quatrieme Partie
منابع مشابه
Leveraging BGP Dynamics to Reverse-Engineer Routing Policies
Inter-domain routing policies are an important component of today’s routing infrastructure. Knowledge about these policies can be used for better traffic engineering, detecting misconfiguration, preventing policy conflicts and also, in understanding Internet routing. However, many domains consider their policies proprietary and rarely reveal them. Hence, techniques that reverse-engineer routing...
متن کاملUnderstanding BGP Anomalies: Detection, Analysis, and Prevention
The Border Gateway Protocol is the de-facto interdomain routing protocol in the Internet. Previous studies and various incidents have shown the vulnerability of the BGP infrastructure to a number of failures. In this paper we address a subset of the problem of BGP vulnerabilities we refer to as BGP anomalies, which can arise both as a result of mistakes by network operators and as a result of m...
متن کاملRouting centralization across domains via SDN: A model and emulation framework for BGP evolution
The Border Gateway Protocol (BGP) was designed almost three decades ago and has many limitations relating to its fully distributed nature, policy enforcement capabilities, scalability, security and complexity. For example, the control plane can take several minutes to converge after a routing change; this may be unacceptable for real-time network services. Despite many research proposals for in...
متن کاملOn Detection of Anomalous Routing Dynamics in BGP
BGP, the de facto inter-domain routing protocol, is the core component of current Internet infrastructure. BGP traffic deserves thorough exploration, since abnormal BGP routing dynamics could impair global Internet connectivity and stability. In this paper, two methods, signature-based detection and statistics-based detection, are designed and implemented to detect BGP anomalous routing dynamic...
متن کاملBGP Behavior Monitoring and Analysis
Border Gateway Protocol, an important inter-domain routing protocol, has a number of vulnerabilities. Little is known about how BGP actually performs in today’s Internet. We designed a framework, BGP Assistant, to monitor and analyze BGP traffic. Number of BGP Updates and Route convergence time are used to characterize BGP behavior. Preliminary results with the Oregon Route Views BGP show that ...
متن کامل