域间路由系统是互联网的关键基础设施,然而它却面临着严重的安全挑战。本文分析了域间路由协议BGP(边界网关协议)存在的脆弱性,构建了域间路由系统攻击模型。阐述了域间路由系统中基于链路和基于路由器节点的攻击模式,并指出这些攻击可能造成的危害.接着讨论了目前正在应用和研究的一些安全对策,并对路由过滤机制和协议扩展两种对策进行了性能比较。
Inter-domain routing system is a critical component of the Interoet routing infrastructure, however, it suffers more and more security problems nowadays. This paper analyses the vulnerabilities of BGP routing protocol, constructing an attack model of inter-domain routing system and expatiating two attack modes in the inter-domain routing system, including the attack mode based on BGP session and BGP routers, and it also indicates what harm these attack can do on the inter-domain routing system. It reviews the main on such attacks, and finally we compare router falter mechanism with protocol extending approach to find which is more effective.