BGP (Border Gateway Protocol) routing trusted verification method based on SDN (Software Defined Network) architecture

A technology of SDN architecture and verification method, which is applied in the field of network security, can solve problems such as no automatic feedback control, no forward compatibility, abnormal routing security monitoring system, etc., achieve good versatility and scalability, and reduce deployment Overhead, the effect of improving verification efficiency

Active Publication Date: 2017-05-10
NAT UNIV OF DEFENSE TECH
View PDF3 Cites 9 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

This method has the following disadvantages: in the digital signature authentication method, each device is required to have two kinds of keys, public key and private key, the key generation, distribution, and maintenance work is cumbersome, the key system is difficult to deploy, and the cost is very high; With the increase of the network scale, the exponential growth of network equipment greatly increases the difficulty of deployment and management of the key system and reduces the overall cost performance of the system.
[0004] Another common way to ensure the credibility of BGP routes is to adopt the BGP route detection system to detect route anomalies. This method has the following disadvantages: 1. The existing route security monitoring system only provides abnormal discovery and alarm services, and does not block abnormalities. function, that is

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • BGP (Border Gateway Protocol) routing trusted verification method based on SDN (Software Defined Network) architecture
  • BGP (Border Gateway Protocol) routing trusted verification method based on SDN (Software Defined Network) architecture
  • BGP (Border Gateway Protocol) routing trusted verification method based on SDN (Software Defined Network) architecture

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0049]The present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation examples.

[0050] Such as figure 1 Shown, a kind of BGP routing credible verification method based on SDN architecture of the present invention, its steps are:

[0051] The first step is to build a trusted verification environment for BGP routing based on the SDN architecture, such as figure 2 As shown, the BGP routing trusted verification environment includes: an agent deployed for each router, and a centralized control point deployed on the client; the agent is responsible for interacting with the BGP protocol process, reading and writing the BGP neighbor information table; the centralized control point is a software The module is responsible for using the network configuration protocol NETCONF (Network Configuration Protocol, Network Configuration Protocol) to periodically interact with the agent, obtain the BGP neighbor informat...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a BGP (Border Gateway Protocol) routing trusted verification method based on SDN (Software Defined Network) architecture. The method comprises the following steps: I, building a BGP routing trusted verification environment based on the SDN architecture; II, acquiring BGP neighbor information by a centralized control point; III, detecting anomalies in a centralized way by the centralized control point, verifying whether BGP routing is trustable or not, if so, ending, otherwise, entering a step IV; IV, generating a security policy for blocking the anomalies by the centralized control point; V, issuing the security policy by the centralized control point to block anomalous routing; and VI, verifying whether the anomalous routing is blocked or not by the centralized control point by a method of reading a BGP neighbor information table once again by an agent, transmitting the BGP neighbor information table to the centralized control point through a NETCONF protocol, and turning to the step III. Compared with an existing BGP routing trusted verification method, the BGP routing trusted verification method disclosed by the invention has the advantages that the deployment overhead can be lowered; the anomaly detection performance and real-time performance are enhanced; the anomalies are blocked through closed-loop control; forward compatibility and high expandability are realized; and the overall cost-performance ratio of a system is increased greatly.

Description

technical field [0001] The present invention mainly relates to the field of network security, in particular to a BGP (Border Gateway Protocol, Border Gateway Protocol) route trustworthy verification method based on an SDN (Software Defined Network, software defined network) architecture. Background technique [0002] Inter-domain routing security is of great significance to the security of the entire Internet. One of the keys to enhancing the security of inter-domain routing is to improve the security of inter-domain routing protocols. BGP protocol is currently the only inter-domain routing protocol, and its security is the key to the security of the entire Internet routing system. Whether the BGP route is trustworthy is the basis for ensuring the security of the BGP protocol. However, at the beginning of BGP design, the issue of trusted routing was not fully considered, and only some simple authentication mechanisms ensured security. In the current complex network environ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): H04L12/715H04L12/721H04L29/06H04L29/08
CPCH04L45/04H04L45/70H04L63/1441H04L67/562
Inventor 邓文平王宝生曾皓苏金树陈曙晖胡宁郦苏丹王宏陶静彭伟唐竹
Owner NAT UNIV OF DEFENSE TECH
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products