路由系统是Intornot的关键基础设施,路由系统的安全关系到核心网络安全.文中对路由系统的安全问题进行归类阐述,分析了历史上典型的安全事件,讨论了各种安全增强方案,提出有效、实用的路由安全监测系统设计方案,描述了系统结构、教据流图,实现了主要功能模块,给出了部署方案和试用效果。该系统能够基于路由表和路由报文对路由行为进行实时监测,发现异常路由和潜在的路由攻击。
Routing system is one of the most important infrastructures of the Internet. And the security of routing system contributes to the security of backbone network, This paper describes various threats on routing system, analyzes some typical security events, and evaluates some existing solutions, and at the same time, proposes an effective design for detection system knownas ISP-Healt. The system's architecture and functions , including its deployment are provided. This system can effectively monitor routing behaviors, and find abnormal routes or hidden routing attacks.