引用本文: | 刘欣,朱培栋,米强,等.基于规则的域间路由系统异常检测.[J].国防科技大学学报,2006,28(3):71-76.[点击复制] |
LIU Xin,ZHU Peidong,MI Qiang,et al.A Rule-based Approach to Anomaly Detection in Inter-domain Routing System[J].Journal of National University of Defense Technology,2006,28(3):71-76[点击复制] |
|
|
|
本文已被:浏览 7080次 下载 5847次 |
基于规则的域间路由系统异常检测 |
刘欣1, 朱培栋1, 米强2, 杨明军1 |
(1.国防科技大学 计算机学院,湖南 长沙 410073;2.国家计算机网络与信息安全管理中心,北京 100029)
|
摘要: |
随着Internet的爆炸性增长,域间路由系统变得越来越复杂并难以控制,许多与域间路由安全相关的事件广泛引起了人们的关注。提出一个基于规则的域间路由监测框架,其中的规则可分为常规异常检测规则和特殊异常检测规则,它们能有效用于检测异常路由和可能的攻击行为,这两种规则的不同在于特殊异常检测规则是由大量路由得到的Internet模型来定义。研究了Internet层次模型与ISP商业关系模型的构造,基于这个框架实现了一个原型系统——ISP-Health,最后给出了检测能力结果。 |
关键词: 域间路由 异常路由 路由攻击 检测规则 |
DOI: |
投稿日期:2005-12-01 |
基金项目:国家863高技术发展计划资助项目(2005AA121570);现代通信国家重点实验室基金资助项目(51436050605KG0102) |
|
A Rule-based Approach to Anomaly Detection in Inter-domain Routing System |
LIU Xin1, ZHU Peidong1, MI Qiang2, YANG Mingjun1 |
(1.College of Computer, National Univ. of Defense Technology, Changsha 410073, China;2.National Network and Information Security Administration Center, Beijing 100029, China)
|
Abstract: |
The behaviors of the Inter-domain Routing (IDR) System are becoming rather complicated with the rapid development of the Internet. Security incidents in IDR system have attracted extensive attention among people. This paper proposes a rule-based monitoring framework to secure IDR System, in which the rules can be used to effectively detect anomalous routes and possible attacks. Unlike GADRs, SADRs were defined according to some Internet models that are behavior-models represented by large numbers of normal routes. Furthermore the construction of the Internet Hierarchy Model and ISP Commercial Relationships Model were studied, and methods based on these models were developed to detect hidden route anomalies or attacks. ISP-Health, the prototype of such a monitoring system supported by the above-mentioned framework, was implemented, and its capabilities were exhibited at last. |
Keywords: inter-domain routing anomalous routes routing attacks detection rule |
|
|
|
|
|