东北大学学报:自然科学版 ›› 2017, Vol. 38 ›› Issue (4): 492-496.DOI: 10.12068/j.issn.1005-3026.2017.04.008

• 信息与控制 • 上一篇    下一篇

Internet路由前缀宣告的特征挖掘与分析

邓文平, 李竹村, 王宏, 高先明   

  1. (国防科学技术大学 计算机学院, 湖南 长沙410073)
  • 收稿日期:2015-04-29 修回日期:2015-04-29 出版日期:2017-04-15 发布日期:2017-04-11
  • 通讯作者: 邓文平
  • 作者简介:邓文平(1981-),男,湖南耒阳人,国防科学技术大学博士研究生; 王宏(1964-),男,湖南益阳人,国防科学技术大学研究员.
  • 基金资助:
    国家自然科学基金资助项目(61202486,61472438).

Characteristics Mining and Analysis for Internet Prefix Announcements

DENG Wen-ping, LI Zhu-cun, WANG Hong, GAO Xian-ming   

  1. School of Computer, National University of Defense Technology, Changsha 410073, China.
  • Received:2015-04-29 Revised:2015-04-29 Online:2017-04-15 Published:2017-04-11
  • Contact: DENG Wen-ping
  • About author:-
  • Supported by:
    -

摘要: 基于大量的历史BGP路由表快照,对BGP路由宣告信息进行深度挖掘.提出了前缀宣告稳定性度量方法,验证了绝大多数路由宣告是稳定的,历史上发生的路由劫持事件都是瞬时的(不具备稳定性);设计了前缀宣告的相似性测度算法,对大量历史BGP路由宣告进行了分析,结果表明大多数大型AS宣告的路由前缀具有自相似性,即,同一个AS宣告的多个路由前缀有一定的连续性.基于以上两个特征,从历史路由信息中可进一步提取前缀宣告的可信集,构造BGP路由宣告的可信知识库,为后续的路由前缀劫持检测和路由安全监测提供依据.

关键词: 前缀宣告, AS, 路由前缀劫持, RouteViews, 特征挖掘

Abstract: The BGP routing information was dogged deeply on the basis of a large number of the history of BGP routing table snapshot. A method to measure stability of prefix announcements was designed, it was verified that vast majority of routing announcement was stable, and the historical routing hijacking was short lived (without stability). A similarity measuring algorithm of prefix announcement was presented, and a large number of the history BGP routing announcements were analyzed. The results showed that the announced prefixes of most large ASes are in line with the property of self-similarity, i.e., the same AS declaring multiple routing prefixes with certain continuity. A trustworthy set of prefix-AS mapping was extracted on the basis of these two characteristics, and a trustworthy knowledge base of BGP routing announcement was designed to provide the basis for prefix hijacking detection and routing security monitoring.

Key words: prefix announcement, autonomous system, prefix hijacking, RouteViews, characteristics mining

中图分类号: