Descartes BGP : A Conflict Detection and Response Framework for Inter - Domain Routing

ثبت نشده
چکیده

—We present Descartes BGP (D-BGP), a fault detection and response framework that enhances the robustness, security, and manageability of inter-domain routing. D-BGP associates a state of " agreement, " " conflict, " or " persistent conflict " with each announced address prefix. When a D-BGP router receives a routing update in which a new AS claims to be an origin of a prefix, it alerts other D-BGP routers to collaboratively verify their ownership claim and resolve the potential conflict without reference to an oracle, such as a topology database server. If a conflict is " persistent, " a black hole may have formed, pulling traffic destined to the prefix in conflict. When this happens, D-BGP logs useful diagnostic information to aid resolution by network administrators. In spite of the black hole, the D-BGP framework allows data traffic to reach critical network services located on or needed by the hosts within the prefix. We evaluate D-BGP with the Scaleable Simulation Framework NETwork (SSFNET) simulator and show that D-BGP resolves BGP faults and misconfigurations in real time, and mitigates a persistent conflict over the ownership of an IP prefix. We show that D-BGP provides path resilience quickly and with few messages. Using BGP update data obtained during an actual black hole event, we show that D-BGP's detection mechanism scales well. «au contraire de cela, même que je pensais à douter de la vérité des autres choses, il suivait très évidemment et très certainement que j'étais.» " to the contrary, in the very act of thinking about doubting the truth of other things, it very clearly and certainly followed that I existed. "-René Descartes (1596-1650), Le Discours de la Méthode, Quatrieme Partie

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Leveraging BGP Dynamics to Reverse-Engineer Routing Policies

Inter-domain routing policies are an important component of today’s routing infrastructure. Knowledge about these policies can be used for better traffic engineering, detecting misconfiguration, preventing policy conflicts and also, in understanding Internet routing. However, many domains consider their policies proprietary and rarely reveal them. Hence, techniques that reverse-engineer routing...

متن کامل

Understanding BGP Anomalies: Detection, Analysis, and Prevention

The Border Gateway Protocol is the de-facto interdomain routing protocol in the Internet. Previous studies and various incidents have shown the vulnerability of the BGP infrastructure to a number of failures. In this paper we address a subset of the problem of BGP vulnerabilities we refer to as BGP anomalies, which can arise both as a result of mistakes by network operators and as a result of m...

متن کامل

Routing centralization across domains via SDN: A model and emulation framework for BGP evolution

The Border Gateway Protocol (BGP) was designed almost three decades ago and has many limitations relating to its fully distributed nature, policy enforcement capabilities, scalability, security and complexity. For example, the control plane can take several minutes to converge after a routing change; this may be unacceptable for real-time network services. Despite many research proposals for in...

متن کامل

On Detection of Anomalous Routing Dynamics in BGP

BGP, the de facto inter-domain routing protocol, is the core component of current Internet infrastructure. BGP traffic deserves thorough exploration, since abnormal BGP routing dynamics could impair global Internet connectivity and stability. In this paper, two methods, signature-based detection and statistics-based detection, are designed and implemented to detect BGP anomalous routing dynamic...

متن کامل

BGP Behavior Monitoring and Analysis

Border Gateway Protocol, an important inter-domain routing protocol, has a number of vulnerabilities. Little is known about how BGP actually performs in today’s Internet. We designed a framework, BGP Assistant, to monitor and analyze BGP traffic. Number of BGP Updates and Route convergence time are used to characterize BGP behavior. Preliminary results with the Oregon Route Views BGP show that ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006