• DocumentCode
    1676927
  • Title

    Credible BGP – Extensions to BGP for Secure Networking

  • Author

    Israr, Junaid ; Guennoun, Mouhcine ; Mouftah, Hussein T.

  • Author_Institution
    Sch. of Inf. Technol. & Eng., Univ. of Ottawa, Ottawa, ON, Canada
  • fYear
    2009
  • Firstpage
    212
  • Lastpage
    216
  • Abstract
    Border Gateway Protocol (BGP) is the de-facto routing protocol in the Internet. Unfortunately, it is not a secure protocol, and as a result, several attacks have been successfully mounted against the Internet infrastructure. Among the security requirements of BGP is the ability to validate the actual source and path of the BGP update message. This is needed to help reduce the threat of prefix hijacking and IP spoofing based attacks. BGP route associates an address prefix with a set of autonomous systems (AS) that identify the inter-domain path that the prefix has traversed in the form of BGP announcements. This set is represented as the AS_PATH attribute in BGP and starts with the AS that originated the prefix. Credible BGP (CBGP) proposes several extensions to BGP protocol to validate source and path of BGP update message and to use the resulting validation score to influence the route selection algorithm. CBGP assigns credibility scores for AS prefix origination and AS_PATH. These credibility scores are used in the extended selection algorithm to prefer valid BGP routes. The new protocol can detect BGP attacks such as AS Path Injection and AS Prefix high jacking.
  • Keywords
    IP networks; Internet; routing protocols; security of data; AS path Injection; BGP update message; IP spoofing; Internet; autonomous systems; border gateway protocol; inter-domain path; prefix hijacking; routing protocols; Data security; IEEE news; IP networks; Information security; Information technology; Internet; Proposals; Protection; Public key; Routing protocols; Credible BGP; IP Spoofing; IRV; S-BGP; SoBGP;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems and Networks Communications, 2009. ICSNC '09. Fourth International Conference on
  • Conference_Location
    Porto
  • Print_ISBN
    978-1-4244-4772-5
  • Electronic_ISBN
    978-0-7695-3775-7
  • Type

    conf

  • DOI
    10.1109/ICSNC.2009.74
  • Filename
    5279360