|
ABSTRACT
We design and evaluate a lightweight route verification mechanism that enables a router to discover route failures and inconsistencies between advertised Internet routes and actual paths taken by the data packets. Our mechanism is accurate, incrementally deployable, and secure against malicious intermediary routers. By carefully avoiding any cryptographic operations in the data path, our prototype implementation achieves the overhead of less than 1% on a 1 Gbps link, demonstrating that our method is suitable even for high-performance networks.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
| |
2
|
E. Billauer. Frandom. http://frandom.sourceforge.net, 2007.
|
 |
3
|
|
| |
4
|
Cisco Systems. Cisco CRS-1 carrier routing system. http://www.cisco.com/application/pdf/en/us/guest/products/ps5763/c1031/cdccont 0900aecd800f8118.pdf.
|
| |
5
|
M. H. DeGroot. Probability and Statistics. Addison-Wesley, 1986.
|
| |
6
|
|
| |
7
|
|
| |
8
|
S. Goldberg, D. Xiao, B. Barak, and J. Rexford. Measuring path quality in the presence of adversaries. http://www.princeton.edu/<goldbe/FDFL-sc.pdf, 2007.
|
| |
9
|
G. Goodell, W. Aiello, T. Griffin, J. Ioannidis, P. McDaniel, and A. Rubin. Working around BGP: An incremental approach to improving security and accuracy of interdomain routing. In Proc. NDSS, 2003.
|
| |
10
|
Iperf. The TCP/UDP bandwidth measurement tool. http://dast.nlanr.net/Projects/Iperf/, 2005.
|
| |
11
|
B. Jenkins. Hash functions and block ciphers. http://www.burtleburtle.net/bob/hash, 2006.
|
| |
12
|
S. Kent, C. Lynn, and K. Seo. Secure Border Gateway protocol (Secure-BGP). IEEE Journal on Selected Areas in Communications, 18(4), 2000.
|
 |
13
|
|
 |
14
|
Ratul Mahajan , David Wetherall , Tom Anderson, Understanding BGP misconfiguration, Proceedings of the 2002 conference on Applications, technologies, architectures, and protocols for computer communications, August 19-23, 2002, Pittsburgh, Pennsylvania, USA
|
 |
15
|
Zhuoqing Morley Mao , Jennifer Rexford , Jia Wang , Randy H. Katz, Towards an accurate AS-level traceroute tool, Proceedings of the 2003 conference on Applications, technologies, architectures, and protocols for computer communications, August 25-29, 2003, Karlsruhe, Germany
[doi> 10.1145/863955.863996]
|
| |
16
|
|
 |
17
|
|
| |
18
|
|
 |
19
|
|
| |
20
|
Alex C. Snoeren , Craig Partridge , Luis A. Sanchez , Christine E. Jones , Fabrice Tchakountio , Beverly Schwartz , Stephen T. Kent , W. Timothy Strayer, Single-packet IP traceback, IEEE/ACM Transactions on Networking (TON), v.10 n.6, p.721-734, December 2002
[doi> 10.1109/TNET.2002.804827]
|
 |
21
|
Ion Stoica , Hui Zhang, Providing guaranteed services without per flow management, Proceedings of the conference on Applications, technologies, architectures, and protocols for computer communication, p.81-94, August 30-September 03, 1999, Cambridge, Massachusetts, United States
|
| |
22
|
Lakshminarayanan Subramanian , Volker Roth , Ion Stoica , Scott Shenker , Randy H. Katz, Listen and whisper: security mechanisms for BGP, Proceedings of the 1st conference on Symposium on Networked Systems Design and Implementation, p.10-10, March 29-31, 2004, San Francisco, California
|
| |
23
|
T. Wan, E. Kranakis, and P. van Oorschot. Pretty secure BGP (psBGP). In Proc. NDSS, 2005.
|
|