ACM Home Page
Please provide us with feedback. Feedback
Real-Time Security Exercises on a Realistic Interdomain Routing Experiment Platform
Full text PdfPdf (628 KB)
Source Workshop on Parallel and Distributed Simulation archive
Proceedings of the 2009 ACM/IEEE/SCS 23rd Workshop on Principles of Advanced and Distributed Simulation - Volume 00 table of contents
Pages 54-63  
Year of Publication: 2009
ISBN ~ ISSN:1087-4097 , 978-0-7695-3713-9
Authors
Publisher
IEEE Computer Society  Washington, DC, USA
Bibliometrics
Downloads (6 Weeks): 20,   Downloads (12 Months): 34,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Review this Article  
DOI Bookmark: 10.1109/PADS.2009.12

ABSTRACT

We use a realistic interdomain routing experiment platform to conduct real-time attack and defense exercises for training purposes. Our interdomain routing experiment platform integrates open-source router software, real-time network simulation, and light-weight machine virtualization technologies, and is capable of supporting realistic large-scale routing experiments. The network model used consists of major autonomous systems connecting Swedish Internet users with realistic routing configurations derived from the routing registry. We conduct a series of real-time security exercises on this routing system to study the consequence of intentionally propagating false routing information on interdomain routing and the effectiveness of corresponding defensive measures. We describe three kinds of simplistic BGP attacks in the context of security exercises designed specifically for training purposes. While an attacker can launch attacks from a compromised router by changing its routing policies, administrators will be able to observe the adverse effect of these attacks and subsequently apply appropriate defensive measures to mitigate their impact,such as installing filtering rules. These exercises, all carried out in real time, demonstrate the feasibility of routing experiments using the real-time routing experiment platform.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
2
 
3
4
 
5
S. Bhatia et al. Hosting virtual networks on commodity hardware. Technical Report GT-CS-07-10, Georgia Tech Computer Science, 2008.
 
6
K. Butler et al. A survey of BGP security issues and solutions. Technical report, AT&T Labs, 2005.
 
7
Y.-J. Chi, R. Oliveira, and L. Zhang. Cyclops: The Internet AS-level observatory. CCR 2008.
 
8
S. Convery and M. Franz. BGP vulnerability testing: Separating fact from FUD v1.1. NANOG 28, 2003.
 
9
 
10
EmuLab. http://www.emulab.net/.
 
11
 
12
 
13
 
14
 
15
 
16
M. Liljenstam. Simulating the national-level impact of routing attacks in Sweden. SNCNW'06. Available at http://liljenstam.net/publication_ docs/sncnw2006.pdf.
 
17
 
18
 
19
 
20
J. Liu et al. An open and scalable emulation infrastructure for large-scale real-time network simulations. INFOCOM'07.
 
21
P. McDaniel. Iseb: Trace driven modeling of Internet scale BGP attacks and countermeasures. DETER/EMIST Workshop 2005.
 
22
S. A. Misel. Wow, AS7007! NANOG mail archives, http://www.merit.edu/mail.archives/ nanog/1997-04/msg00340.html, 1997.
 
23
OpenVPN. http://www.openvpn.net/.
 
24
OpenVZ. http://openvz.org/.
 
25
PlanetLab. http://www.planet-lab.org/.
 
26
B. Quoitin and S. Uhlig. Modeling the routing of an autonomous system with C-BGP. IEEE Network, 19(6), 2005.
 
27
RIPE NCC. http://www.ripe.net/.
 
28
RIPE NCC. YouTube hijacking: A RIPE NCC RIS case study. http://www.ripe.net/news/ study-youtube-hijacking.html, 2008.
 
29
Routeviews. http://www.routeviews.org.
 
30
G. Siganos and M. Faloutsos. Analyzing BGP policies: methodology and tool. INFOCOM'04.
 
31
VMWare Workstation. http://www.vmware.com/ products/ws/.
 
32
XORP users mailing list. http://mailman.icsi. berkeley.edu/pipermail/xorp-users/ 2008-April/002515%.html.
 
33
K. Zetter. Revealed: The Internet's biggest security hole. http://blog.wired.com/27bstroke6/ 2008/08/revealed-the-in.html.
34

Collaborative Colleagues:
Yue Li: colleagues
Michael Liljenstam: colleagues
Jason Liu: colleagues