摘要
本文在全面分析域间路由安全威胁的基础上提出实现域间路由安全的系统化方法,从安全策略检测、路由协议增强、路由器健壮性设计、路由行为监测以及安全能力测试等多个角度来增强域间路由系统的安全能力,并建立域间路由系统的安全能力模型;探讨了各种安全功能的交互关系、多视图之间的互补与合作以及安全能力部署等问题;同时,给出了路由器安全配置检测工具、安全测试工具和路由监测系统的基本实现方案。
Based on the thorough analysis of secure threats of interdomain routing systems, the paper proposes a systematic approach to improving system security, which integrates policy checker, protocol enhancement, router robustness design, .behavior monitoring and security testing. The security capability model of inter-domain routing is built, and the relations between different security methods and their deployment are discussed. The designs of some efficient tools are also presented including configuration verifier, security tester and muting monitor.
出处
《计算机工程与科学》
CSCD
2006年第2期10-13,19,共5页
Computer Engineering & Science
基金
国家自然科学基金资助项目(90204005)
国家863计划资助项目(2003AA121510)
关键词
域间路由
安全
策略
协议增强
监测
能力模型
inter-domain routing
security
policy
protocol enhancement
monitoring
capability model