Incrementally-Deployable Security for Interdomain Routing

  • Authors:
  • Jennifer Rexford;Joan Feigenbaum

  • Affiliations:
  • -;-

  • Venue:
  • CATCH '09 Proceedings of the 2009 Cybersecurity Applications & Technology Conference for Homeland Security
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

The Internet’s interdomain-routing system is extremely vulnerable to accidental failure, configuration errors, and malicious attack. Any successful approach to improving interdomain-routing security must satisfy two requirements for incremental deployability: backwards compatibility with the existing routing protocol and installed base of routers and incentive compatibility with the desire of each domain to improve its part of the routing system even if other domains have not taken similar steps. We propose an incrementally deployable approach based on a Routing Control Platform (RCP) that makes routing decisions on behalf of the routers in a domain, without requiring changes to the routers or protocols. The RCP runs anomaly-detection algorithms that identify, and avoid, suspicious routes, allowing a domain (or a small group of cooperating domains) to significantly improve interdomain routing security.