多源AS冲突可能起源于多宿主,如配置错误或者恶意攻击等。路由安全要求区分多源AS冲突中的错误或者恶意的路由。对多源AS冲突进行严格定义,分析产生原因和严重后果,设计并实现了解决方案——MOAS LIST机制,并进行了真实场景实验。组网测试结果表明,MOAS LIST机制仅能发现潜在的错误或恶意路由,需要网管参与才能最终确定其正误,为更加安全机制的建立提供了宝贵的指导建议。
Multiple origin AS conflicts may result from multi-homing, misconfiguration or malicious attack. To differentiate routes owing to the latter two causes from others is strongly required for routing security. The MOAS LIST mechanism is one of countermeasures. MOAS a strict definition is given, its cause and bad effect are analyzed. This mechanism is designed and implemented for deep study. Real experiments display: The MOAS LIST can only point out those routes which may be wrong. Network operator should take measures to assure it. So better mechanism should be designed.