Route determination method, system and device and storage medium

By constructing a BGP routing knowledge graph and a multi-dimensional reputation evaluation model, the problem of insufficient security in the BGP protocol is solved, and the security constraints and stability of routing selection are improved, making it adaptable to complex network environments.

CN120956649APending Publication Date: 2025-11-14CHINA INTERNET NETWORK INFORMATION CENTER
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511442555.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

The BGP protocol lacks inherent security mechanisms and is vulnerable to threats such as route hijacking and path forgery. Traditional routing lacks security constraints and is difficult to adapt to complex and ever-changing network environments.

Method used

A BGP routing knowledge graph is constructed, and the reputation value of autonomous system nodes is calculated through a multi-dimensional reputation evaluation model. A set of trustworthy routes is selected, and the optimal route is selected by performing a reputation-weighted scoring.

Benefits of technology

It implements security constraints on route selection, improves the security and reliability of BGP routes, adapts to complex and ever-changing network environments, and enhances the stability of the routing system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956649A_ABST
    Figure CN120956649A_ABST
Patent Text Reader

Abstract

The invention discloses a route determination method, system and device and a storage medium. The method comprises the steps of obtaining route notification data and a candidate route set; constructing a knowledge graph based on the route notification data, and calculating a reputation value of each autonomous domain node based on the knowledge graph; and based on the reputation value of each autonomous domain node, screening out a credible route set from the candidate route set, performing reputation weighted scoring on paths in the credible route set, and selecting the path with the highest score as the optimal route. Semantic organization is carried out on the autonomous domain, the routing prefix and the strategy relation through the knowledge graph, the data availability and analysis efficiency are improved, dynamic evaluation of the autonomous domain reputation is achieved in combination with neighbor recommendation, and the accuracy of credibility judgment is improved; a reputation evaluation result is directly applied to path selection, untrusted nodes and paths are effectively filtered, potential attack risks are reduced, and the overall security and stability of a routing system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a routing determination method, system, device, and storage medium. Background Technology

[0002] Border Gateway Protocol (BGP) is the core protocol for inter-domain routing on the Internet, responsible for exchanging network reachability information between different Autonomous Systems (AS). However, BGP lacked inherent security mechanisms in its initial design, and its trust-based operation makes it vulnerable to security threats such as route hijacking, path forgery, and false advertising. These threats can lead to large-scale network traffic disruptions, the theft or alteration of user data, and seriously threaten the stability and security of the Internet.

[0003] Traditional methods for ensuring route security primarily rely on static policies or single metrics for trustworthiness assessment. Static policies, like unchanging rulebooks, cannot be adjusted in time to adapt to dynamic changes in the network environment and are ill-suited to complex and ever-changing network scenarios. For example, some static policies may be based on a fixed network topology or preset security thresholds, but these policies become ineffective when the network topology changes or new attack methods emerge, failing to accurately assess the trustworthiness of nodes. Therefore, current routing selection lacks security constraints. Summary of the Invention

[0004] To address the aforementioned issues, this application provides a route determination method, system, device, and storage medium.

[0005] The embodiments of this application disclose the following technical solutions:

[0006] The first aspect of this application provides a route determination method, including:

[0007] Retrieve route announcement data and candidate route set;

[0008] A knowledge graph is constructed based on routing announcement data. The knowledge graph includes multiple entities and the relationships connecting the entities. The entities include autonomous system nodes, prefixes, and routing policies. The relationships include adjacency relationships describing direct connections between autonomous system nodes, path relationships describing the path of routing prefixes between autonomous system nodes, and policy constraint relationships describing the impact of routing policies on path selection.

[0009] Based on the knowledge graph, the reputation value of each autonomous domain node is calculated;

[0010] Based on the reputation value of each autonomous system node, a set of trusted routes is selected from the candidate route set. The paths in the set of trusted routes do not contain autonomous system nodes with reputation values ​​lower than a preset threshold.

[0011] The paths in the trusted route set are given a reputation-weighted score, and the path with the highest score is selected as the optimal route.

[0012] In one possible implementation, calculating the reputation value of each autonomous region node based on the knowledge graph includes:

[0013] Based on the routing behavior data represented by the knowledge graph, the index values ​​of each autonomous domain node under multiple evaluation dimensions are calculated.

[0014] The local reputation value of each autonomous system node is obtained by weighting the index values ​​under the multiple evaluation dimensions.

[0015] In one possible implementation, the plurality of evaluation dimensions includes at least two of the following:

[0016] The announcement deviation rate measures the authenticity and stability of routing announcements published by autonomous system nodes; information completeness reflects the sufficiency of information in routing announcements published by autonomous system nodes; and historical stability is used to analyze the consistency of routing behavior of autonomous system nodes based on time series analysis.

[0017] In one possible implementation, calculating the reputation value of each autonomous system node based on the knowledge graph includes:

[0018] Obtain at least one neighboring autonomous region node from the knowledge graph that has an adjacency relationship with the target autonomous region node;

[0019] Obtain the reputation recommendation value provided by at least one neighboring autonomous system node to the target autonomous system node;

[0020] The comprehensive reputation value of the target autonomous system node is obtained by weighted aggregation of the local reputation value and the reputation recommendation value.

[0021] In one possible implementation, the reputation-weighted scoring of paths in the trusted route set includes:

[0022] The arithmetic mean of the reputation values ​​of all autonomous system nodes in the path is used as the reputation score for that path.

[0023] In one possible implementation, the construction of the knowledge graph includes:

[0024] Define the ontology structure of the knowledge graph, including autonomous regions, prefixes, routing policies, and connection relationship entities;

[0025] The routing data is mapped into entities and relations represented as triples using an entity-relation extraction algorithm.

[0026] The triples are stored in a graph database to obtain the knowledge graph.

[0027] This application provides a route determination system in embodiment two, including:

[0028] The acquisition unit is used to acquire route announcement data and candidate route set;

[0029] A construction unit is used to construct a knowledge graph based on routing announcement data. The knowledge graph includes multiple entities and relationships connecting the entities. The entities include autonomous system nodes, prefixes, and routing policies. The relationships include adjacency relationships describing direct connections between autonomous system nodes, path relationships describing the path of routing prefixes between autonomous system nodes, and policy constraint relationships describing the impact of routing policies on path selection.

[0030] A computing unit is used to calculate the reputation value of each autonomous domain node based on the knowledge graph;

[0031] The filtering unit is used to filter out a set of trusted routes from the candidate route set based on the reputation value of each autonomous system node, wherein the paths in the set of trusted routes do not contain autonomous system nodes with reputation values ​​lower than a preset threshold.

[0032] The selection unit is used to perform reputation-weighted scoring on the paths in the trusted route set and select the path with the highest score as the optimal route.

[0033] A third aspect of this application provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the routing determination method as described in the first aspect above.

[0034] A fourth aspect of this application provides a computer program product that, when run on a computer, executes the routing determination method as described in the first aspect above.

[0035] A fifth aspect of this application provides a computer-readable storage medium storing instructions that, when executed on a terminal device, cause the terminal device to perform the routing determination method as described in the first aspect above.

[0036] Compared with the prior art, this application has the following beneficial effects:

[0037] By acquiring route advertisement data, a knowledge graph is constructed containing entities such as autonomous system nodes, prefixes, and routing policies, as well as adjacency relationships, path relationships, and policy constraints. This transforms scattered routing information into a structured semantic network, clearly tracing the route prefix transmission path and autonomous system connection logic, effectively identifying threats such as route hijacking and path forgery, and compensating for the lack of security mechanisms in the BGP protocol. Secondly, the reputation value of autonomous system nodes is calculated based on the knowledge graph. Leveraging the dynamic update characteristics of the knowledge graph and multi-dimensional data support, dynamic and multi-dimensional evaluation of node trustworthiness is achieved, overcoming the limitations of traditional methods that rely on static policies or single indicators, and adapting to complex and ever-changing network environments. Finally, a set of trustworthy routes without low-reputation nodes is first selected based on reputation value thresholds. Then, the paths within the set are weighted by reputation and the optimal route is selected, effectively ensuring the security of route selection, solving the problem of lack of security constraints in traditional route selection, and comprehensively improving the security and reliability of BGP routes. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0039] Figure 1 A flowchart illustrating a route determination method provided in an embodiment of this application;

[0040] Figure 2 This is a schematic diagram of the knowledge graph construction process provided in an embodiment of this application;

[0041] Figure 3 This is a structural diagram of a routing determination system provided in an embodiment of this application. Detailed Implementation

[0042] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0043] To facilitate understanding of the technical solutions provided in the embodiments of this application, the technical terms involved in the embodiments of this application will be explained below.

[0044] BGP (Border Gateway Protocol), as the core protocol for inter-domain routing on the Internet, undertakes the crucial task of exchanging routing information and selecting paths between different Autonomous Systems (AS). It informs each AS of "which IP address blocks (routing prefixes) can be reached via which paths" by transmitting routing advertisements between routers at the boundaries of ASs, thereby helping to form an interconnected routing topology for the globally dispersed network.

[0045] To facilitate understanding of the technical solutions provided in the embodiments of this application, the background technology involved in the embodiments of this application will be described below.

[0046] As mentioned earlier, existing technologies primarily enhance BGP routing security through route authentication protocols (such as RPKI), route filtering policies, and anomaly detection mechanisms. However, these methods have the following shortcomings:

[0047] First, there is a lack of systematic routing knowledge management. Existing solutions mostly rely on scattered routing logs or table data for analysis. The data is fragmented and unstructured, making it difficult to support global analysis and dynamic updates across autonomous systems, and failing to achieve a comprehensive understanding and modeling of the entire inter-domain routing system.

[0048] Second, the reputation assessment mechanism is imperfect. Traditional routing security methods mainly rely on static policies or single indicators to judge credibility, lacking a multi-dimensional and dynamic node reputation evaluation system, making it difficult to accurately reflect the historical behavior and real-time status of an autonomous system.

[0049] Third, routing selection lacks security constraints. During path calculation, most algorithms prioritize performance metrics such as hop count, latency, or bandwidth, while failing to adequately constrain node reputation and information authenticity. This may lead to the selection of routes that include untrusted nodes, thereby creating potential security risks.

[0050] To address the aforementioned issues, this application constructs a BGP routing knowledge graph, achieving structured and semantic management of routing information and laying a data foundation for global routing analysis. Based on this, a dynamic reputation evaluation model integrating multi-dimensional indicators and a neighbor recommendation mechanism significantly improves the accuracy of node credibility determination. Furthermore, the reputation evaluation results are directly applied to the routing decision-making process. Through security filtering and reputation-weighted scoring mechanisms, optimal path selection under security constraints is achieved, fundamentally enhancing the security and stability of the routing system. Thus, this application forms a unified system integrating knowledge management, reputation evaluation, and secure routing, possessing excellent scalability and adaptability, capable of working collaboratively with existing security protocols, and effectively addressing various security threats faced by BGP routing.

[0051] It should be noted that the routing determination method, system, device, and medium provided in this application can be applied to the field of computer technology. The above are merely examples and do not limit the application field of the routing determination method, system, device, and medium provided in this application. Furthermore, the embodiments of this application may not limit the executing entity of the routing determination; for example, the routing determination method of this application embodiment can be applied to data processing devices such as terminal devices or servers. The terminal device can be an electronic device such as a computer or a personal digital assistant (PDA). The server can be a standalone server, a cloud server, or a cluster server composed of multiple servers.

[0052] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0053] The following embodiment illustrates a route determination method provided in this application. See also... Figure 1 ,Should Figure 1 A flowchart of a route determination method provided in this application embodiment, the method including:

[0054] S101. Obtain route advertisement data and candidate route set.

[0055] When a data packet needs to be sent from the source to the destination, the BGP protocol typically provides multiple reachable AS paths. This set contains all currently available potential paths to the destination. For example, to reach the same destination, there may be paths [AS1, AS2, AS3], [AS1, AS4, AS5], and [AS1, AS6, AS7], and these three paths constitute the candidate route set.

[0056] Routing advertisement data can be collected from publicly available BGP routing advertisements on the Internet, and can contain four key types of information, providing basic data support for subsequent knowledge graph construction and reputation assessment:

[0057] Routing prefix: such as 192.168.0.0 / 24, is used to identify IP address blocks and is the core identifier for routing.

[0058] Path information: namely, the Autonomous System Path (AS-PATH), which records the path sequence of route prefixes passed between different Autonomous Systems (AS), such as AS1→AS2→AS3.

[0059] Announcement time: The specific time when the autonomous system publishes this route announcement, which is used for subsequent historical stability analysis and time series data processing;

[0060] Autonomous System Identifier (AS): also known as AS number, such as AS174 or AS4837, uniquely identifies an autonomous system node on the Internet and is the key basis for establishing relationships between autonomous systems.

[0061] In one possible implementation, the collected raw BGP route advertisement data can be processed in three steps: "cleaning, formatting, and anomaly detection" to ultimately form a standardized route dataset, including the following steps:

[0062] The first step is data cleaning. This involves removing invalid information from the original data. The operations include:

[0063] Delete duplicate records. If two records have the same routing prefix, AS-PATH, and announcement time, they are considered duplicates. Duplicate data may be caused by redundant transmission or update delays from the collector. Keep the first occurrence of the record and delete subsequent duplicates to avoid statistical biases, such as incorrect path length calculations.

[0064] Remove invalid data, i.e., filter announcement records with incorrect formats or missing key fields (such as AS number and routing prefix), to ensure that each data entry has complete analytical value. Specifically, check whether the prefix format conforms to IPv4 / IPv6 specifications (e.g., 192.0.2.0 / 24 is valid, 192.0.2.0 / 33 is invalid). Invalid prefixes may be caused by configuration errors or malicious injection.

[0065] The second step is to standardize the format of the cleaned and valid data, including:

[0066] Routing prefix format verification, that is, according to the classless inter-domain routing standard, verifying the legality of the combination of IP address range and subnet mask of the prefix, such as excluding records with masks such as "192.168.0.0 / 33" that are out of reasonable range;

[0067] Autonomous system identifier standardization means converting AS numbers into a uniform numerical format, such as excluding invalid AS identifiers with non-numeric characters, to ensure the uniqueness and consistency of autonomous system node identifiers;

[0068] The time format is standardized, which means converting the announcement time into a standard timestamp or "year-month-day hour:minute:second" format to facilitate subsequent time series analysis.

[0069] The third step is to identify and remove outliers. This involves eliminating extreme values ​​or erroneous records from the data to prevent interference with subsequent analysis.

[0070] After the above three steps, a standardized routing dataset with standardized fields, complete information, and no anomalies is obtained. This dataset will be directly used in the subsequent "BGP routing knowledge graph construction" stage as the basic data source for extracting entities (autonomous regions, routing prefixes, etc.) and relationships (adjacency relationships, path relationships, etc.).

[0071] S102. Construct a knowledge graph based on routing announcement data.

[0072] The knowledge graph is constructed in a top-down manner, first defining the framework and then filling in the data. First, the core concept system and hierarchical structure of the BGP routing system are clarified, and then entities and relationships are extracted and mapped based on the standardized routing dataset to ensure the semantic consistency and structure of the knowledge graph and adapt to the global analysis needs of inter-domain routing systems.

[0073] Entities are the core nodes in a knowledge graph. The main entities include Autonomous Systems (AS), prefixes, routing policies, and peer links. An Autonomous System node represents an independent network management organization (such as an ISP or a large corporate network). A prefix represents a block of IP addresses, which are network-reachable destinations. A routing policy represents the business or technical rules followed by an AS in routing selection.

[0074] Relationships are the edges that connect entities, giving data context and meaning. Relationships include adjacency relationships, path relationships, and policy constraint relationships. Adjacency relationships describe the direct connections between ASs; path relationships describe the propagation paths of routing prefixes between different ASs; policy constraint relationships describe the impact of routing policies on path selection.

[0075] In one possible implementation, the construction of the knowledge graph includes: defining the ontology structure of the knowledge graph, including autonomous systems, prefixes, routing policies, and connection entities; mapping routing data into entities and relations represented in the form of triples using an entity relation extraction algorithm; and storing the triples in a graph database to obtain the knowledge graph.

[0076] A graph database is used for knowledge graph construction and storage. Through relation fusion and attribute indexing, a complete routing knowledge network is established, supporting efficient retrieval and visual analysis. (Definition of the knowledge graph) ,in Represents a set of entities. Represents a set of relations. Represents a set of attributes, and uses triples It represents the relationship between entities.

[0077] See Figure 2 , Figure 2This diagram illustrates the knowledge graph construction process provided in this application embodiment. Data download involves acquiring relevant data from RIPE, RouteViews, and third-party data sources. These data sources provide rich network routing information, forming the basis for subsequent processing. The downloaded compressed data is decompressed and converted into a directly processable format. Invalid, duplicate, or erroneous information is cleaned from the data to improve data quality and ensure the accuracy of subsequent processing. Data extraction involves extracting key information needed to construct the knowledge graph from the cleaned data. Relationship mining involves analyzing the extracted data to uncover inherent relationships between data, such as associations between network entities. Data storage involves storing the data after relationship mining to provide data support for knowledge graph construction.

[0078] The updates primarily involve changes and improvements to the three key elements of the knowledge graph: entities, relationships, and attributes.

[0079] An entity refers to a node in a knowledge graph that represents a specific thing, such as an Autonomous System (AS) or prefix in a BGP routing knowledge graph. Entity updates mean adding, modifying, or deleting information about these nodes. For example, when a new autonomous system appears, a corresponding entity node needs to be added to the knowledge graph, along with its identifier, geographical location, and other information; if the name or number of an autonomous system changes, the information of existing entity nodes needs to be modified; if an autonomous system no longer participates in network routing activities, the corresponding entity node needs to be deleted.

[0080] In a BGP routing system, there are adjacency relationships, path relationships, and so on. Relationship updates involve adjusting these connection relationships. For example, when a new peer connection is established between two autonomous systems, an adjacency edge between the two autonomous system entities needs to be added to the knowledge graph; if the propagation path of a route prefix changes, the path relationship between the prefix entity and the relevant autonomous system entity needs to be modified.

[0081] Attributes are information that describes the characteristics of entities and relationships. For example, attributes of an autonomous system (AS) entity might include its region and network size, while attributes of adjacency relationships might include connection establishment time and bandwidth. Attribute updates involve correcting and supplementing this descriptive information. For instance, when the network size of an AS changes, or the bandwidth of an adjacency relationship is upgraded, the corresponding attribute values ​​need to be updated promptly.

[0082] S103. Based on the knowledge graph, calculate the reputation value of each autonomous domain node.

[0083] By leveraging the rich structured historical behavioral data in the knowledge graph, a quantitative and dynamic credibility score is calculated for each AS node.

[0084] In one possible implementation, calculating the reputation value of each autonomous system node based on the knowledge graph includes: calculating the indicator value of each autonomous system node under multiple evaluation dimensions based on the routing behavior data represented by the knowledge graph; and performing a weighted calculation on the indicator values ​​under the multiple evaluation dimensions to obtain the local reputation value of each autonomous system node.

[0085] Routing behavior data comes directly from the constructed knowledge graph. As a structured database, the knowledge graph records the historical behavior of each AS node, such as: which routing prefixes it publishes? Whether its AS path is stable or changes frequently, whether the routing information it advertises is complete (e.g., whether it contains complete community attributes), and whether it has advertised invalid or inappropriate prefixes (i.e., route leakage or hijacking).

[0086] Traditional reputation assessments rely on a single metric (such as whether an attack has been launched). This method, however, is based on knowledge graphs and can calculate multi-dimensional metrics, such as:

[0087] Advertisement Deviation Rate: The degree to which the routing information published by this AS deviates from recognized authoritative data (such as RPKI) or historical norms. Path Stability: Whether the paths appearing in the path relationships of this AS change frequently and drastically. Policy Consistency: Whether its behavior violates its declared or common routing policies. Through these multi-dimensional indicators, a more comprehensive and accurate reputation score is calculated, and this value can be dynamically updated as new data is added.

[0088] For example, the following explains how to calculate multi-dimensional reputation metrics:

[0089] Announcement Deviation Rate The deviation between the announced and actual network status can be measured using the following method:

[0090]

[0091] Information integrity The method used to measure the completeness of a notice's content can be:

[0092]

[0093] Historical stability The calculation method can reflect the continuity and consistency of behavior within an autonomous region:

[0094]

[0095] The node reputation score is calculated by combining various dimensions of indicators using a weighted approach.

[0096] (Formula 1)

[0097] in, The weights can be determined based on the sensitivity of the indicators and / or empirical data.

[0098] In one possible implementation, node reputation is calculated using a weighted formula, incorporating reputation recommendations from neighboring autonomous systems. Neighboring nodes providing high-quality recommendations are awarded points to increase the incentive for information sharing and enhance the overall credibility of the assessment.

[0099] Specifically, at least one neighboring autonomous system node with an adjacency relationship to the target autonomous system node is obtained from the knowledge graph; the reputation recommendation value provided by the at least one neighboring autonomous system node to the target autonomous system node is obtained; and the comprehensive reputation value of the target autonomous system node is obtained by weighted aggregation based on the local reputation value of the target autonomous system node and the reputation recommendation value.

[0100] To improve the credibility of the assessment, an inter-autonomous region reputation recommendation mechanism is introduced. The overall reputation value of a node is a weighted aggregation of its local reputation and the recommendation values ​​of its neighboring nodes:

[0101] (Formula 2)

[0102] in For local evaluation weights, This is the recommended set of nodes.

[0103] One possible implementation is to introduce a reputation-based referral incentive mechanism to reward nodes that provide high-quality recommendations, thereby increasing participation enthusiasm through reputation enhancement.

[0104] Node AS200 submits a reputation recommendation score (e.g., 0.9) for AS100 based on its direct interaction experience with AS100. The system does not blindly trust all recommendations. It evaluates whether the recommendation provided by AS200 is of high quality.

[0105] Criteria for determining "high quality" may include: Consistency: Does AS200's recommendation align with the recommendations of most other neighbors? Accuracy: Does AS200's recommendation match the actual behavior subsequently exhibited by AS100? (For example, AS200 reports low reputation for AS100, and AS100 subsequently experiences a route hijacking incident). Historical record: Have AS200's past recommendations been consistently reliable? Once the system determines that AS200 has provided a high-quality recommendation, it will be immediately rewarded.

[0106] The reward is an increase in AS200's overall reputation score. For example, if AS200's original reputation score was 0.88, the system would raise it to 0.90 based on its demonstrated "honesty" and "insight".

[0107] S104. Based on the reputation value of each autonomous system node, select a set of trusted routes from the candidate route set.

[0108] In one possible implementation, constructing the knowledge graph includes: defining the ontology structure of the knowledge graph, including autonomous systems, prefixes, routing policies, and connection entities; mapping routing data into entities and relations represented as triples using an entity relation extraction algorithm; and storing the triples in a graph database to obtain the knowledge graph. This ensures that subsequent optimization selections will only be performed within a secure path pool composed of high-reputation nodes, thus avoiding the selection of routes passing through malicious or unreliable nodes from the outset.

[0109] Candidate routes are security-filtered based on node reputation values, removing routes with reputation values ​​below a threshold. The nodes yield a set of trusted routes. :

[0110] (Formula 3)

[0111] in, This is the filtered candidate route set. For path nodes.

[0112] S105. Perform reputation-weighted scoring on the paths in the trusted route set, and select the path with the highest score as the optimal route.

[0113] Within a set of paths that have achieved basic security, the "overall credibility" of each path is further quantified, and the safest path is selected. This not only satisfies the hard constraint of "security" (all nodes meeting the reputation standard) but also pursues "greater security" (the highest overall reputation for the entire path). This optimizes routing decisions in terms of security.

[0114] The arithmetic mean of the reputation values ​​of all autonomous system nodes along the path is calculated as the reputation score for that path. This is then applied to candidate routing paths. The formula for calculating the credit weighted score is:

[0115] (Formula 4)

[0116] in, This represents the overall reputation value of the path nodes. This represents the number of nodes in the path.

[0117] Under the premise of satisfying policy constraints, the path with the highest score is selected as the optimal route, realizing dynamic routing decision-making that balances security and performance. The specific algorithm flow is shown in Algorithm 1.

[0118]

[0119] By constructing a BGP routing knowledge graph, traditional fragmented and unstructured routing data (such as AS paths and prefix advertisements) is transformed into a semantically related network of entities and relationships. This enables unified modeling and visualization analysis of routing data, supports global routing behavior analysis and dynamic updates across autonomous systems, and greatly improves the availability and efficiency of routing data analysis.

[0120] This paper proposes a node reputation evaluation model based on multi-dimensional indicators (such as notification deviation rate, information integrity, and historical stability), which overcomes the limitations of traditional static or single-indicator evaluations. A neighbor recommendation mechanism and an incentive mechanism are introduced to achieve dynamic updating and community-based evaluation of node reputation, significantly improving the accuracy of reputation evaluation and the system's resistance to attacks.

[0121] By using node reputation as the core constraint for routing selection, and through security filtering and reputation-weighted scoring, the system shifts its routing decision-making from a "performance-first" approach to a "balance between security and performance." This effectively identifies and avoids potentially malicious nodes and untrusted paths, significantly improving the security and stability of the routing system.

[0122] It can be integrated with existing routing security protocols (such as RPKI), anomaly detection mechanisms, and policy control modules to build a comprehensive protection system; at the same time, it supports indicator weight adjustment and algorithm expansion, and has good environmental adaptability and future evolution capabilities.

[0123] The above are some specific implementations of the routing determination method provided in the embodiments of this application. Based on this, this application also provides a corresponding routing determination system. The system provided in the embodiments of this application will be described below from the perspective of functional modularity. Figure 3 This is a structural diagram of a routing determination system provided in an embodiment of this application.

[0124] The system includes:

[0125] Acquisition unit 110 is used to acquire route advertisement data and candidate route set;

[0126] Construction unit 111 is used to construct a knowledge graph based on routing announcement data. The knowledge graph includes multiple entities and relationships connecting the entities. The entities include autonomous system nodes, prefixes, and routing policies. The relationships include adjacency relationships describing direct connections between autonomous system nodes, path relationships describing the path of routing prefixes between autonomous system nodes, and policy constraint relationships describing the impact of routing policies on path selection.

[0127] The computing unit 112 is used to calculate the reputation value of each autonomous domain node based on the knowledge graph;

[0128] The filtering unit 113 is used to filter a set of trusted routes from the candidate route set based on the reputation value of each autonomous system node, wherein the paths in the set of trusted routes do not contain autonomous system nodes with reputation values ​​lower than a preset threshold.

[0129] Selection unit 114 is used to perform reputation-weighted scoring on the paths in the trusted route set and select the path with the highest score as the optimal route.

[0130] This application also provides corresponding devices and computer storage media for implementing the routing determination scheme provided in this application.

[0131] The device includes a memory and a processor. The memory stores instructions or code, and the processor executes the instructions or code to cause the device to perform the routing determination method described in any embodiment of this application.

[0132] The computer storage medium stores code, and when the code is run, the device running the code implements the routing determination method described in any embodiment of this application.

[0133] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems or apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and relevant parts can be referred to the method section.

[0134] It should be understood that in this application, "at least one" refers to one or more items, and "more" refers to two or more items. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one" or similar expressions refer to any combination of these items, including any combination of singular or plural items. For example, "at least one" of a, b, or c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.

[0135] It should be understood that the terms center, longitudinal, transverse, up, down, front, back, left, right, vertical, horizontal, top, bottom, inside, outside, etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the present invention.

[0136] It should be noted that, unless otherwise explicitly specified and limited, the terms installation, connection, and linking should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0137] It should also be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the statement "comprising a..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0138] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0139] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A route determination method, characterized in that, include: Retrieve route announcement data and candidate route set; A knowledge graph is constructed based on routing announcement data. The knowledge graph includes multiple entities and the relationships connecting the entities. The entities include autonomous system nodes, prefixes, and routing policies. The relationships include adjacency relationships describing direct connections between autonomous system nodes, path relationships describing the path of routing prefixes between autonomous system nodes, and policy constraint relationships describing the impact of routing policies on path selection. Based on the knowledge graph, the reputation value of each autonomous domain node is calculated; Based on the reputation value of each autonomous system node, a set of trusted routes is selected from the candidate route set. The paths in the set of trusted routes do not contain autonomous system nodes with reputation values ​​lower than a preset threshold. The paths in the trusted route set are given a reputation-weighted score, and the path with the highest score is selected as the optimal route.

2. The method according to claim 1, characterized in that, The calculation of the reputation value of each autonomous region node based on the knowledge graph includes: Based on the routing behavior data represented by the knowledge graph, the index values ​​of each autonomous domain node under multiple evaluation dimensions are calculated. The local reputation value of each autonomous system node is obtained by weighting the index values ​​under the multiple evaluation dimensions.

3. The method according to claim 2, characterized in that, The multiple evaluation dimensions include at least two of the following: The announcement deviation rate measures the authenticity and stability of routing announcements published by autonomous system nodes; information completeness reflects the sufficiency of information in routing announcements published by autonomous system nodes; and historical stability is used to analyze the consistency of routing behavior of autonomous system nodes based on time series analysis.

4. The method according to claim 2, characterized in that, The calculation of the reputation value of each autonomous region node based on the knowledge graph includes: Obtain at least one neighboring autonomous region node from the knowledge graph that has an adjacency relationship with the target autonomous region node; Obtain the reputation recommendation value provided by at least one neighboring autonomous system node to the target autonomous system node; The comprehensive reputation value of the target autonomous system node is obtained by weighted aggregation of the local reputation value and the reputation recommendation value.

5. The method according to claim 1, characterized in that, The reputation-weighted scoring of paths in the trusted route set includes: The arithmetic mean of the reputation values ​​of all autonomous system nodes in the path is used as the reputation score for that path.

6. The method according to claim 1, characterized in that, The construction of the knowledge graph includes: Define the ontology structure of the knowledge graph, including autonomous regions, prefixes, routing policies, and connection relationship entities; The routing data is mapped into entities and relations represented as triples using an entity-relation extraction algorithm. The triples are stored in a graph database to obtain the knowledge graph.

7. A route determination system, characterized in that, include: The acquisition unit is used to acquire route announcement data and candidate route set; A construction unit is used to construct a knowledge graph based on routing announcement data. The knowledge graph includes multiple entities and relationships connecting the entities. The entities include autonomous system nodes, prefixes, and routing policies. The relationships include adjacency relationships describing direct connections between autonomous system nodes, path relationships describing the path of routing prefixes between autonomous system nodes, and policy constraint relationships describing the impact of routing policies on path selection. A computing unit is used to calculate the reputation value of each autonomous domain node based on the knowledge graph; The filtering unit is used to filter out a set of trusted routes from the candidate route set based on the reputation value of each autonomous system node, wherein the paths in the set of trusted routes do not contain autonomous system nodes with reputation values ​​lower than a preset threshold. The selection unit is used to perform reputation-weighted scoring on the paths in the trusted route set and select the path with the highest score as the optimal route.

8. A computer program product, characterized in that, The computer-readable storage medium stores instructions that, when executed on a terminal device, cause the terminal device to perform the routing determination method as described in any one of claims 1-6.

9. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the routing determination method as described in any one of claims 1-6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a terminal device, cause the terminal device to perform the routing determination method as described in any one of claims 1-6.

Citation Information

Cited By

  • Service migration method and system giving consideration to reputation and fault-tolerant mechanism

    CN121547460A

  • A service migration method and system considering reputation and fault tolerance mechanism

    CN121547460B