摘要
路由系统是Internet的关键基础设施,路由系统的安全关系到核心网络安全。文中对路由系统的安全问题进行归类阐述,分析了历史上典型的安全事件,讨论了各种安全增强方案,提出有效、实用的路由安全监测系统设计方案,描述了系统结构、数据流图,实现了主要功能模块,给出了部署方案和试用效果。该系统能够基于路由表和路由报文对路由行为进行实时监测,发现异常路由和潜在的路由攻击。
Routing system is one of the most important infrastructures of the Internet. And the security of routing system contributes to the security of backbone network, This paper describes various threats on routing system, analyzes some typical security events, and evaluates some existing solutions, and at the same time, proposes an effective design for detection system knownas ISP-Healt. The system's architecture and functions , including its deployment are provided. This system can effectively monitor routing behaviors, and find abnormal routes or hidden routing attacks.
出处
《信息安全与通信保密》
2007年第8期178-181,共4页
Information Security and Communications Privacy
基金
国家自然科学基金(No.60673169)
国家高技术研究发展计划863项目(No.2006AA01Z213)
现代通信国家重点实验室基金(51436050605KG0102)
关键词
域间路由系统
态势可视化
安全监测
inter-domain routing
situation visualization
safety monitoring