清华大学学报(自然科学版)  2015, Vol. 55 Issue (11): 1229-1234    DOI: 10.16511/j.cnki.qhdxxb.2015.21.017
黎松1, 段海新2, 李星1,2
1. 清华大学电子工程系, 北京 100084;
2. 清华大学网络科学与网络空间研究院, 北京 100084
Real-time system for detecting inter-domain routing man-in-the-middle attacks
LI Song1, DUAN Haixin2, LI xing1,2
1. Department of Electronic Engineering, Tsinghua University, Beijing 100084, China;
2. Institute of Network Science and Cyberspace, Tsinghua University, Beijing 100084, China
摘要 针对域间路由中间人攻击这一域间路由安全面临的新威胁,建立攻击模型并分析其在路由控制平面和数据平面所产生的异常特征,进而提出一种域间路由中间人攻击的实时检测系统。该系统首先通过控制平面异常监控发现可疑的异常路由,之后进行数据平面转发路径探测以鉴别该异常是否为域间路由中间人攻击。实际网络部署的测试结果表明:该系统是轻量级的,并能实时有效地检测出可能的域间路由中间人攻击。
关键词 域间路由前缀劫持中间人攻击检测    
Abstract:Man-in-the-middle attacks have become a new serious threat to inter-domain routing. This paper presents a real-time system for detecting inter-domain routing man-in-the-middle attacks based on an analysis of a threat model and key features in the control plane and the data plane. The detection system first monitors the anomalous route in the control plane and then probes the data plane to identify the inter-domain routing man-in-the-middle attack. Internet tests show that the detection system is light-weight and effectively detects probable man-in-the-middle attacks in inter-domain routing in real time.
Key wordsinter-domain routing    prefix hijacking    man-in-the-middle attack    detection
收稿日期: 2015-08-31      出版日期: 2015-11-15
通讯作者: 段海新,教授,     E-mail:
黎松, 段海新, 李星. 域间路由中间人攻击的实时检测系统[J]. 清华大学学报(自然科学版), 2015, 55(11): 1229-1234.
LI Song, DUAN Haixin, LI xing. Real-time system for detecting inter-domain routing man-in-the-middle attacks. Journal of Tsinghua University(Science and Technology), 2015, 55(11): 1229-1234.
  图1 域间路由中间人攻击模型
  图2 多宿主产生的合法MOAS与延长距离为1的域间路由中间人攻击
  图3 域间路由中间人攻击实时检测系统框架
  图4 域间路由中间人攻击检测算法
  图5 每天的MITM 报警数和报警前缀数
  图6 延长距离大于1的MITM 报警实例
