期刊文献+

基于自治域协同的域间路由信誉模型 被引量:1

An inter-domain routing reputation model based on autonomous domain collaboration
原文传递
导出
摘要 域间路由系统自治域间的交互缺乏可信认证,建立针对自治域行为模式的信誉模型可为域间路由管理提供约束与激励,提高整体安全水平.由于域间路由系统分布自治、局部路由信息不完整,现有信誉评价方法无法从全局视角感知自治域行为,难以准确反映自治域可信程度及其变化.本文提出一种基于自治域协同的域间路由信誉模型.首先通过分析自治域路由行为统计特征,建立基于贝叶斯(Bayes)后验概率分析的自治域信誉量化指标,用于对目标自治域进行本地信誉评价;然后通过研究自治域属性与本地路由信息完整程度的关系,设计信誉加权聚合算法,采用多域协同方式计算目标自治域的全局信誉评价;最后设计信誉动态更新方法,以对连续恶意行为的自治域进行惩罚.基于真实安全事件的实验结果表明,该模型能够有效聚合各自治域本地信誉评价,捕捉自治域行为在不同时间阶段的细微变化,可为域间路由系统中异常路由抑制、安全事件溯源和供应商选取提供参考. Interactions between autonomous systems(ASes)in inter-domain routing systems lack credibility authentication.Establishing a reputation model to evaluate AS behaviors can provide constraints and incentives for inter-domain routing management,thus improve the overall security.Due to the autonomous distributed nature and incomplete local routing information of inter-domain routing systems,existing reputation evaluation methods cannot perceive AS behaviors in a global perspective and reflect AS credibility dynamics accurately.We propose an inter-domain routing reputation model based on autonomous domain collaboration.We first analyze statistical characteristics of AS routing behaviors and establish a Bayesian-estimation-based AS reputation quantification index to evaluate local reputation of the target AS;Then,based on our investigation of relationships between AS properties and its local routing information integrity,we design a weighted reputation aggregation algorithm to compute global reputation of target AS in a multi-domain collaborative manner;Finally,we introduce a reputation updating method to penalize ASes with continuous malicious behaviors.Experimental results based on real incidents show that,the proposed model can effectively aggregate local reputation evaluations of participant ASes and capture AS behavior dynamics in different phases.The model can be used for abnormal routing suppression,security event source tracing,and provider selection in inter-domain routing systems.
作者 陈迪 邱菡 祝凯捷 王清贤 朱俊虎 Di CHEN;Han QIU;Kaijie ZHU;Qingxian WANG;Junhu ZHU(Institute of Cyberspace Security,Information Engineering University,Zhengzhou 450002,China;State Key Laboratory of Mathematical Engineering and Advanced Computing,Zhengzhou 450002,China;State Key Laboratory of Complex Electromagnetic Environment Effect on Electronic and Information System,Luoyang 471003,China)
出处 《中国科学:信息科学》 CSCD 北大核心 2021年第9期1540-1558,共19页 Scientia Sinica(Informationis)
基金 国家自然科学基金(批准号:61502528,61902447)资助项目。
关键词 域间路由安全 自治域行为 信誉模型 贝叶斯估计 inter-domain routing security autonomous system behaviors reputation model Bayesian estimation
  • 相关文献

参考文献6

二级参考文献116

  • 1李德毅,刘常昱.论正态云模型的普适性[J].中国工程科学,2004,6(8):28-34. 被引量:882
  • 2卢锡城,赵金晶,朱培栋,董攀.域间路由系统自组织特性[J].软件学报,2006,17(9):1922-1932. 被引量:10
  • 3Rekhter Y, Li T, Hares S. A border gateway protocol (BGP Version 4). IETF Internet RFC, RFC 4271. 2006.
  • 4Butler K, Farley T, McDaniel P, Rexford J. A survey of BGP security. 2005. http://www.patrickmcdaniel.org/pubs/td-5ugj33.pdf.
  • 5Roughgarden T. Selfish routing [Ph.D. Thesis]. Comell University, 2002.
  • 6Bono VJ. 7007 explanation and apology. 1997. http://www.merit.edu/mail.archives/nanog/1997-04/msg00444.html.
  • 7Popescu AC, Premore BJ, Underwood T. Abstract: Anatomy of a leak: AS9121. 2005. http://www.nanog.org/mtg-0505/ underwood.html.
  • 8Brown MA. Pakistan hijacks YouTube: A closer look. 2008. http://www.circleid.com/posts/82258_pakistan_hijacks_youtube_closer_look.
  • 9PResnick P, Zeckhauser R, Friedman E, Kuwabara K. Reputation systems: Facilitating trust in Internet interactions. Communications of the ACM, 2000,43(12):45-48.
  • 10The North American Network Operators' Group. 2008. http://www.nanog.org/.

共引文献41

同被引文献3

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部