前缀劫持攻击是互联网BGP域问路由系统中的首要安全威胁,至今还无有效解决该问题的方案。以前缀劫持攻击为研究对象,分析了前缀劫持攻击产生的具体原因,展现了该攻击在自治系统内部以及在自治系统之间的表现形式与影响;从前缀劫持攻击的危害程度,分析并划分了前缀劫持攻击的基本形态,讨论了各种前缀劫持攻击的基本特性。分析结果表明,子前缀劫持的危害最严重,确切前缀劫持的影响最复杂,而父前缀劫持最易被发现且危害相对较小。
Prefix hijacking is the primary security threat in the Internet' s BGP system,and presently there is no effective solution against it. Taking the prefix hijacking as the research object, analyze the causes of producing prefix hijacking, showing the form and influence of attack within the autonomous system and between autonomous systems. From the damage degree of prefix hijacking, analyze and divide the basic form of prefix hijacking,and discuss the basic characteristics of various prefix hijackings. The results show that the sub-prefix hijacking is of the most serious hazards, the exact prefix hijacking' s impact is the most complex, while the father prefix hijacking is found most easily and the smallest harm relatively.