Sign what you really care about - Secure BGP AS-paths efficiently

  • Authors:
  • Yang Xiang;Xingang Shi;Jianping Wu;Zhiliang Wang;Xia Yin

  • Affiliations:
  • Tsinghua National Laboratory for Information Science and Technology (TNList), Beijing 100084, PR China and Department of Computer Science & Technology, Tsinghua University, Beijing 100084, PR Chin ...;Tsinghua National Laboratory for Information Science and Technology (TNList), Beijing 100084, PR China and Institute for Network Sciences and Cyberspace, Tsinghua University, Beijing 100084, PR Ch ...;Tsinghua National Laboratory for Information Science and Technology (TNList), Beijing 100084, PR China and Department of Computer Science & Technology, Tsinghua University, Beijing 100084, PR Chin ...;Tsinghua National Laboratory for Information Science and Technology (TNList), Beijing 100084, PR China and Institute for Network Sciences and Cyberspace, Tsinghua University, Beijing 100084, PR Ch ...;Tsinghua National Laboratory for Information Science and Technology (TNList), Beijing 100084, PR China and Department of Computer Science & Technology, Tsinghua University, Beijing 100084, PR Chin ...

  • Venue:
  • Computer Networks: The International Journal of Computer and Telecommunications Networking
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

The de facto inter-domain routing protocol, Border Gateway Protocol (BGP), plays a critical role in the reliability of the Internet routing system. However, the system may also be devastated by forged BGP routes that are generated by malicious attacks or mis-configurations. This security problem has attracted considerable attention, and although several solutions has been proposed, none of them have been widely deployed due to weaknesses such as high computational cost or potential security vulnerability. This paper proposes Fast Secure BGP (FS-BGP), an efficient mechanism that can secure AS-paths and prevent prefix hijacking by signing critical AS-path segments. We prove that FS-BGP achieves a similar level of security as S-BGP, but with much higher efficiency. Compared with S-BGP, the cost of signing and verification in FS-BGP can be reduced by orders of magnitude, as demonstrated in our experiments using BGP UPDATE data collected from real backbone routers. Indeed, the signing and verification can be accomplished as fast as the most bursty BGP UPDATE arrivals, which implies that FS-BGP will hardly delay the propagation of routing information.