基于大量的历史BGP路由表快照,对BGP路由宣告信息进行深度挖掘.提出了前缀宣告稳定性度量方法,验证了绝大多数路由宣告是稳定的,历史上发生的路由劫持事件都是瞬时的(不具备稳定性);设计了前缀宣告的相似性测度算法,对大量历史BGP路由宣告进行了分析,结果表明大多数大型AS宣告的路由前缀具有自相似性,即,同一个AS宣告的多个路由前缀有一定的连续性.基于以上两个特征,从历史路由信息中可进一步提取前缀宣告的可信集,构造BGP路由宣告的可信知识库,为后续的路由前缀劫持检测和路由安全监测提供依据.
aThe BGP routing information was dogged deeply on the basis of a large number of the history of BGP routing table snapshot.A method to measure stability of prefix announcements was designed,it was verified that vast majority of routing announcement was stable,and the historical routing hijacking was short lived(without stability).A similarity measuring algorithm of prefix announcement was presented,and a large number of the history BGP routing announcements were analyzed.The results showed that the announced prefixes of most large ASes are in line with the property of self-similarity,i.e.,the same AS declaring multiple routing prefixes with certain continuity.A trustworthy set of prefix-AS mapping was extracted on the basis of these two characteristics,and a trustworthy knowledge base of BGP routing announcement was designed to provide the basis for prefix hijacking detection and routing security monitoring.