An accurate distributed scheme for detection of prefix interception

来源 :Science China(Information Sciences) | 被引量 : 0次 | 上传用户:lcg512
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Previous research in interdomain routing security has often focused on prefix hijacking. However,several prefix interception events have happened lately, which poses a new security challenge to the interdomain routing system. Compared to prefix hijacking, prefix interception is much harder to detect, as it avoids black hole by forwarding the hijacked traffic back to the victim. In this paper, we present a novel method to detect prefix interception. Our approach exploits a key observation about prefix interception: during a prefix interception event, the attacker detours the intercepted traffic through its network, which turns it into a new important“transit point” for access to the victim. By collecting data plane information to detect the emerging “transit point” and using control plane information to verify it, our scheme can identify prefix interception in real time.The results of Internet experiments and Internet-scale simulations show that our method is accurate with low false alarm rate(0.28%) and false negative rate(2.26%). Previous research in interdomain routing security has often focused on prefix hijacking. However, several prefix interception events have happened lately, which poses a new security challenge to the interdomain routing system. Compared to prefix hijacking, prefix interception is much harder to detect, as it avoid black hole by forwarding the hijacked traffic back to the victim. In this paper, we present a novel observation to prefix interception; the attacker detours the intercepted traffic through its network, which turns it into a new important “transit point ” for access to the victim. “By collecting data plane information to detect the emerging ” transit point "and using control plane information to verify it, our scheme can identify prefix interception in real time. The results of Internet experiments and Internet-scale simulations show that our method is accurate with low false alarm rate (0.28%) and false negative rate (2.26%).
其他文献
期货市场的基本经济功能是指期货市场本身所特有的、内在的、本质的、基本的经济功能和效能,目前普遍认为,期货市场的基本功能有两个,即套期保值功能和价格发现功能。期货市
AIM: To investigate the role of Gadd45 a in hepatic fibrosis and the transforming growth factor(TGF)-β/Smad signaling pathway.METHODS: Wild-type male BALB/c mi
把小猫、小狗、小兔子们集合起来办场宠物时装表演赛,那多么有意思啊!喜爱小动物的胡溪成立了工作室让宠物服装也能追着时尚走。 How cute is to bring cats, puppies, and bu
最近,互联网上刮起了一场由一个炫老头引起的时尚风。炫老头究竟是何方神圣,目前尚未知,但炫老头的举动却轰动了网民。在“Kappa潮人搭”活动中,一个长相平平的老头一改中国老年人传统搭配,穿着时尚、新潮,动作前卫,与无数年轻的美女帅哥们一比高下。炫老头的疯狂举动被网友爆料后,引起众多网民关注,炫老头也迅速蹿红网络。可见,当前时尚不分年龄,追求快乐不再固守传统界限,已经成为一种主潮流。    在国外,时
你经常参加各种聚会,如果其中有情投意合的异性,聚会将会非常有意思。但是也不乏会遇到一些无聊的聚会。遇到这样的情况,你会找什么借口离开呢?  A.“无聊,我回去了。”  B.“对不起,我家教很严。”  C.“我身体有些不舒服。”  D.“哦,差点忘了,我还要赶赴一个约会。”    您选择A:你无需使用什么招数,只需要堂堂正正地参与竞争就可以获得爱情。但是美中不足的是,直线出击往往容易失败。当恋爱不能
(1)人们对待题材的态度历来有两种,一种是曾经长期统治文坛、诗界的“题材决定论”,认为有某种“重大题材”的存在,所以诗人、作家必须去写重大题材,另一种是“无须题材论”
今天,我们的思维已经很习惯于电视的逻辑。电视上播放的内容已经入侵到个人生活的每个角落,图像、信息传播成为家庭生活无法缺少的一部分。电视传播的审美、道德、标准等以
1、面试前一定要做好homework2、从哪些角度去做research3、永远保持活力和竞争力4、细节决定成败5、面试官最想要什么TIPS1、面试之前的homework准备求职的朋友或即将毕业的
百家争鸣之风在中国由来已久,而诸多疑难问题正是在学者们的争论声中,变得浅白,而后昭然于天下。作为编者,我们虽只耕耘于这一方文字天地,亦愿博闻多见,希望多听一点“不同的声音”
目的评价彩色多普勒超声对肝前性门静脉高压的诊断价值。方法回顾2012年6月-2015年1月9例确诊为肝前性门静脉高压患者的彩色多普勒超声表现,观察受累血管内径、形态、血流性