Inter-domain route selection method based on reputation evaluation and related device
By subdividing the behavioral impact of autonomous systems and conducting multi-cycle reputation assessments, the problems of incomplete reputation assessments and lack of feedback in existing technologies are solved, resulting in more accurate inter-domain routing and enhanced security.
Patent Information
- Application Number
- CN202211188895.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-03-03
- Filing Date
- 2022-09-27
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2042-09-27
AI Technical Summary
Existing reputation-based inter-domain routing methods fail to fully consider the behavioral details of autonomous systems (AS) and lack an assessment of the impact of routing event propagation, resulting in a lack of effective feedback mechanisms when illegal routes spread.
By calculating the declared reputation and routing reputation of the Autonomous System Alliance (AS) to the target AS, combining observation weights, the behavioral impact of the AS is subdivided, and the reputation assessment results of multiple periods are integrated to screen out accurate inter-domain routes.
It improves the accuracy of route selection, effectively identifies and prevents the spread of illegal routes, and enhances the security of inter-domain routing systems.
Smart Images

Figure CN115801655B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this application relate to the technical fields of routing systems and network security, and in particular to a reputation-based inter-domain routing selection method and related equipment. Background Technology
[0002] In existing reputation-based inter-domain routing methods, most reputation mechanisms simply divide the behavior of an Autonomous System (AS) into legal and illegal behaviors, without describing the detailed information of the AS's behavior, and the consideration of reputation value calculation is not comprehensive.
[0003] Furthermore, the impact of infected ASs on the spread of routing events is not considered. In other words, in inter-domain routing systems, illegal routes need to be spread and propagated through other ASs besides the malicious AS. Therefore, ASs that forward illegal routes bear an unshirkable responsibility for the spread of false information, especially nodes closer to the source of false information. The existing reputation mechanism lacks a feedback mechanism for those who forward routing messages.
[0004] Therefore, a solution is needed that can construct a reputation mechanism by finely classifying the behavior of AS. Summary of the Invention
[0005] In view of this, the purpose of this application is to propose an inter-domain routing method and related equipment based on reputation assessment.
[0006] To achieve the above objectives, this application provides a reputation-based inter-domain routing method, including:
[0007] Within the current evaluation period, identify multiple other autonomous systems that can be observed by each of the multiple autonomous system alliances in the communication network, and use them as multiple target autonomous systems corresponding to the autonomous system alliance;
[0008] For each target autonomous region, calculate the declared reputation of the target autonomous region with respect to each of the corresponding autonomous region associations in the current evaluation period; and calculate the routing and forwarding reputation of the target autonomous region with respect to each of the corresponding autonomous region associations in the current evaluation period.
[0009] For each target autonomous region, the local reputation of each corresponding autonomous region alliance to the target autonomous region is calculated in the current evaluation period using the declared reputation and the routing reputation of each corresponding autonomous region alliance.
[0010] For each Autonomous Region Alliance (AGA), the observation weight of the AGA is determined based on the AGA's observations of all corresponding target AGAs. For each target AGA, the local reputation of the target AGA is determined using all the corresponding AGA alliances, and based on the observation weights of each, the first global reputation independently evaluated in the current period is determined. Using the first global reputation, combined with the first global reputation of the target AGA evaluated in the previous period, the second global reputation of the target AGA in the current evaluation period is calculated.
[0011] Based on two preset autonomous systems, multiple initial routes between the two autonomous systems are determined. Using a preset reputation threshold, multiple candidate routes are selected from the multiple initial routes. For each candidate route, a route reputation value is calculated using the second global reputation of each autonomous system in the candidate route. Based on the route reputation values of each candidate route, a target route between the two autonomous systems is determined.
[0012] Further, the declared reputation of the target autonomous region with respect to each of the corresponding autonomous region federations is calculated within the current evaluation period, including:
[0013] For each target autonomous region (AUR), the legal declaration utility value and illegal declaration utility value observed by the corresponding AUR alliance are determined. Using the accumulated legal declaration utility value and accumulated illegal declaration utility value, the declaration reputation of the target AUR with respect to the corresponding AUR alliance is calculated according to the following formula:
[0014]
[0015] Where N represents the target autonomous region being observed, u represents the autonomous region alliance that performs the observation of the target autonomous region, and T u,A (N) represents the declared reputation of the autonomous domain alliance u towards the target autonomous domain N. This represents the accumulated legal declaration utility value of the target autonomous region N. This represents the accumulated illegal declaration utility value of the target autonomous region N.
[0016] Further, the routing and forwarding reputation of the target autonomous system with respect to each of the corresponding autonomous system associations is calculated within the current evaluation period, including:
[0017] For each target autonomous system, the legal routing utility value and illegal routing utility value observed by the corresponding autonomous system association are determined. Using the accumulated legal routing utility value and the accumulated illegal routing utility value, the routing reputation of the target autonomous system with respect to the corresponding autonomous system association is calculated using the following formula:
[0018]
[0019] Among them, T u,E (N) represents the routing and forwarding reputation of the autonomous region alliance u to the target autonomous region N. This represents the accumulated legitimate routing forwarding utility value for the target autonomous system N. This represents the accumulated illegal routing utility value of the target autonomous system N.
[0020] Furthermore, for each Autonomous Region Alliance (AGA), the observation weights of the AGA are determined based on its observations of all corresponding target AGAs, including:
[0021] For each target autonomous region, determine the autonomous region alliance that will observe the target autonomous region;
[0022] The observation weights for the target autonomous region are determined using the formula shown below:
[0023]
[0024] Among them, W u (N) represents the observation weight of the autonomous region consortium u to the target autonomous region N;
[0025] The legal declaration of the target autonomous region N as observed by the autonomous region consortium u;
[0026] The illegal declaration observed by the autonomous region consortium u in the target autonomous region N;
[0027] This refers to the legal route forwarding observed by the autonomous region alliance u for the target autonomous region N;
[0028] This refers to the illegal route forwarding observed by the autonomous region alliance u in the target autonomous region N;
[0029] express At least one target autonomous region is affected;
[0030] express At least one target autonomous region is affected;
[0031] express At least one target autonomous region is affected;
[0032] express At least one target autonomous region is affected;
[0033] P A,t express For any target autonomous region in W(P) A,t ) represents P A,t The weights;
[0034] P A,f express For any target autonomous region in W(P) A,f ) represents P A,f The weights;
[0035] P E,t express For any target autonomous region in W(P) E,t ) represents P E,t The weights;
[0036] P E,f express For any target autonomous region in W(P) E,f ) represents P E,f The weight.
[0037] Further, the first global reputation independently assessed within the current period is determined. Using the first global reputation and combining it with the first global reputation of the target autonomous region assessed in the previous period, the second global reputation of the target autonomous region in the current assessment period is calculated, including:
[0038] For the target autonomous region, using the determined observation weights, the local reputations of each entity in the target autonomous region are weighted and aggregated according to the following formula to obtain the first global reputation:
[0039]
[0040] Among them, T g (N) represents the first global reputation, T u (N) represents the local reputation of the autonomous region alliance u on the target autonomous region N, where the first global reputation is calculated independently within the current period.
[0041] Based on the assessment of the target autonomous region in the previous assessment period, and according to the set time decay coefficient, the second global reputation for the current assessment period is determined using the following formula:
[0042]
[0043] Among them, GT k (N) represents the second global reputation in the current k-th evaluation period. This represents the first global reputation of the target autonomous region N at the current k-th evaluation period, σ represents the preset time decay coefficient, and GT k-1(N) represents the second global reputation determined in the (k-1)th evaluation period.
[0044] Furthermore, multiple candidate routes are selected from the multiple initial routes, including:
[0045] For each of the initial routes, perform the following operation:
[0046] Determine the second global reputation value for each autonomous system in the initial route;
[0047] Determine whether the second global reputation value of each autonomous region is lower than the preset reputation threshold;
[0048] If the second global reputation value of any autonomous system in the initial route is greater than or equal to the preset reputation threshold, then the initial route is selected as the candidate route.
[0049] Further, the route reputation value is calculated using the second global reputation of each of the candidate autonomous systems, and the target route between the two autonomous systems is determined based on the route reputation value of each candidate route, including:
[0050] The route reputation value for each candidate route is calculated using the following formula:
[0051]
[0052] Among them, T r N represents the route reputation value of candidate route r. i Let k represent the i-th target autonomous system on candidate route r. i This indicates the preset N. i The weights;
[0053] Sort all the candidate routes in descending order of their respective route reputation values;
[0054] Determine the difference between the highest route reputation value and the reputation values of all other routes;
[0055] If the difference exceeds a predetermined difference threshold, the candidate route corresponding to the route reputation value is excluded.
[0056] Using a preset route selection mechanism, a target route is determined from the candidate routes that have never been excluded.
[0057] Based on the same inventive concept, this application also provides an inter-domain routing selection device based on reputation assessment, including: a preprocessing module, a reputation declaration and routing forwarding reputation calculation module, a local reputation calculation module, a second global reputation calculation module, and a target route determination module;
[0058] The preprocessing module is configured to, within the current evaluation period, identify multiple other autonomous systems that can be observed by each of the multiple autonomous system alliances in the communication network, and use them as multiple target autonomous systems corresponding to the autonomous system alliance.
[0059] The declared reputation and routing reputation calculation module is configured to, for each target autonomous region, calculate the declared reputation of the target autonomous region with respect to each of the corresponding autonomous region associations in the current evaluation period; and calculate the routing reputation of the target autonomous region with respect to each of the corresponding autonomous region associations in the current evaluation period.
[0060] The local reputation calculation module is configured to, for each target autonomous region, use the declared reputation and the routing reputation of each corresponding autonomous region alliance to calculate the local reputation of each corresponding autonomous region alliance to the target autonomous region within the current evaluation period.
[0061] The second global reputation calculation module is configured to: for each autonomous region alliance, determine the observation weight of the autonomous region alliance based on the observations of the autonomous region alliance on all corresponding target autonomous regions; for each target autonomous region, use the local reputation of the target autonomous region by all corresponding autonomous region alliances and determine the first global reputation independently evaluated in the current period based on the observation weights of each; and use the first global reputation, combined with the first global reputation of the target autonomous region evaluated in the previous period, to calculate the second global reputation of the target autonomous region in the current evaluation period.
[0062] The target route determination module is configured to determine multiple initial routes between two preset autonomous systems, filter multiple candidate routes from the multiple initial routes using a preset reputation threshold, calculate a route reputation value for each candidate route using the second global reputation of each autonomous system in the candidate route, and determine the target route between the two autonomous systems based on the route reputation value of each candidate route.
[0063] Based on the same inventive concept, this application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the inter-domain routing method based on reputation assessment as described above.
[0064] Based on the same inventive concept, this application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions for causing the computer to perform the inter-domain routing selection method based on reputation assessment as described above.
[0065] As can be seen from the above, the reputation-based inter-domain routing method and related equipment provided in this application calculate local reputation based on the observations of other autonomous systems by the AS alliance and by comprehensively considering the advertised reputation and routing reputation of the target AS. This allows for the subdivision of the impact of different behaviors of the target AS and, in conjunction with multiple AS alliances that implement the observations corresponding to the target AS, determines the second global reputation value under the overall situation. Furthermore, it comprehensively considers the first global reputation value assessment conducted independently of other periods within each period, as well as the assessment results from other periods, to determine the second global reputation value. This makes the second global reputation value take into account factors such as time decay, thereby obtaining a more accurate assessment result and improving the accuracy of routing selection. Attached Figure Description
[0066] To more clearly illustrate the technical solutions in this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0067] Figure 1 This is a flowchart illustrating the inter-domain routing method based on reputation assessment, as described in an embodiment of this application.
[0068] Figure 2 This is a schematic diagram of the routing selection logic in an embodiment of this application;
[0069] Figure 3 This is a schematic diagram of the inter-domain routing selection device based on reputation assessment according to an embodiment of this application;
[0070] Figure 4 This is a schematic diagram of the electronic device structure according to an embodiment of this application. Detailed Implementation
[0071] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.
[0072] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects.
[0073] As described in the background section, existing reputation-based inter-domain routing methods are still insufficient to meet the needs of routing selection in actual production.
[0074] In the process of implementing this application, the applicant discovered that the main problems with the relevant reputation-based inter-domain routing methods are as follows: First, most reputation mechanisms simply divide the behavior of an AS (Autonomous Region) into legal and illegal behaviors, without describing the detailed information of the AS's behavior, and the consideration of reputation value calculation is not comprehensive.
[0075] Furthermore, the impact of infected ASs on the spread of routing events is not considered. In other words, in inter-domain routing systems, illegal routes need to be spread and propagated through other ASs besides the malicious AS. Therefore, ASs that forward illegal routes bear an unshirkable responsibility for the spread of false information, especially nodes closer to the source of false information. The existing reputation mechanism lacks a feedback mechanism for those who forward routing messages.
[0076] Based on this, the reputation-based inter-domain routing method proposed in this application is proposed.
[0077] The embodiments of this application are described in detail below with reference to the accompanying drawings.
[0078] refer to Figure 1 One embodiment of the inter-domain routing method based on reputation assessment in this application includes the following steps:
[0079] Step S101: Within the current evaluation period, identify multiple other autonomous systems that can be observed by each of the multiple autonomous system alliances in the communication network, and use them as multiple target autonomous systems corresponding to the autonomous system alliance.
[0080] In the embodiments of this application, firstly, in the communication network, each AS alliance (Autonomous Domain Alliance) in the inter-domain routing system is determined. In this embodiment, an AS alliance is a collection of autonomous domains composed of a group of closely related ASs.
[0081] As can be seen, each AS alliance contains multiple AS nodes, and these AS nodes can cooperate with each other to complete pre-specified tasks.
[0082] Each AS alliance has a leader node, and each AS in the AS alliance has multiple VPs (Visitor Points) so that the AS alliance can observe multiple other ASs. Furthermore, in each observation period (which can also be called the evaluation period in this embodiment), the AS establishes a Peer relationship with its neighboring AS through the VP. The Peer relationship means that the AS can collect and parse routing snapshots and update message information.
[0083] Furthermore, all other ASs that can be observed by the AS alliance are taken as target ASs (target autonomous regions) with respect to the AS alliance, and the set of all target ASs corresponding to the AS alliance is taken as the service domain of the AS alliance.
[0084] Furthermore, the VP within the AS alliance can send the observed service domain information to the alliance leader node after an observation period ends.
[0085] It can be seen that for an AS alliance that performs observation, multiple target ASs can be observed, and a target AS can be observed by multiple AS alliances. That is, an AS alliance can correspond to multiple different target ASs, and a target AS can also correspond to multiple different AS alliances. Furthermore, it can be determined that any AS in an AS alliance can serve as an AS that performs observation, and can also serve as a target AS corresponding to other AS alliances when observed by other AS alliances.
[0086] In this embodiment, the behavior of any AS can be divided into: route advertisement, route forwarding and path hijacking; further, route advertisement is divided into: legitimate route advertisement and illegitimate route advertisement; and route forwarding is divided into legitimate route forwarding and illegitimate route forwarding.
[0087] Among them, legitimate route announcement means that the AS announces its own prefix; illegitimate route announcement means that the AS announces a prefix that does not belong to itself, which is also known as source hijacking; legitimate route forwarding means that the AS learns a new legitimate route and correctly forwards the legitimate route to its neighboring AS; path hijacking means that the AS tampers with the route update information and forwards it to its neighboring AS; illegitimate route forwarding means that the AS does not actively carry out path hijacking or source hijacking attacks, but forwards routes from attackers.
[0088] Step S102: For each target autonomous system, calculate the declared reputation of the target autonomous system with respect to each corresponding autonomous system association in the current evaluation period; and calculate the routing and forwarding reputation of the target autonomous system with respect to each corresponding autonomous system association in the current evaluation period.
[0089] In the embodiments of this application, based on the target AS corresponding to each AS alliance determined in the foregoing steps, and the AS alliance corresponding to each target AS, when selecting the best route for any AS in a specified AS alliance, firstly, in each evaluation period, the advertised reputation and route forwarding reputation of each target AS corresponding to that AS alliance are calculated.
[0090] In this embodiment, based on a defined AS alliance that implements observations, the declared reputation of each target AS can be calculated using the accumulated legitimate declared utility value and the accumulated illegitimate declared utility value.
[0091] Specifically, the legal declaration utility value for the target AS refers to the value assigned to the legal route declaration made by the target AS. When the AS alliance that is determined to perform the observation observes the target AS making a legal route declaration, a legal declaration utility value corresponding to the legal route declaration behavior and corresponding to the AS alliance that performs the observation is generated for the target AS.
[0092] Furthermore, the illegal declaration utility value of the target AS refers to the value assigned to the illegal route declaration made by the target AS. Specifically, when the AS alliance that is determined above observes that the target AS makes an illegal route declaration, an illegal declaration utility value corresponding to the illegal route declaration behavior and corresponding to the AS alliance that is conducting the observation is generated for the target AS.
[0093] It can be seen that the utility values of legal declarations and illegal declarations are corresponding. That is to say, when describing the aforementioned two utility values, it is necessary to clarify that the utility value is the value evaluated by the AS consortium that carried out the observation for its corresponding specific target AS. However, the above utility values evaluated by other different AS consortia that carried out the observation for the same target AS are different.
[0094] Furthermore, the cumulative legal and illegal declared utility values of the AS consortium implementing the observations for the target AS assessment were determined.
[0095] Specifically, the cumulative legally declared utility value of the AS consortium implementing the observations for the target AS is expressed by the following formula:
[0096]
[0097] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. This represents the accumulated legal declaration utility value of the target autonomous region N, and this legal declaration utility value is the assessment of the target autonomous region N based on the observations of the AS consortium u. This refers to the legitimate declaration of the target autonomous region N observed by the AS consortium u; express The service domain, that is, the service domain described by AS consortium u. The set of all other ASs that can be affected, where γ represents the preset first coefficient, P A,t express For any target AS in the array, W(P) A,t Then it means P A,t The weight.
[0098] Furthermore, the cumulative illegal declaration utility value of the AS consortium implementing the observations for the target AS is expressed by the following formula:
[0099]
[0100] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. This represents the accumulated illegal declaration utility value of the target autonomous region N, and this illegal declaration utility value is an assessment of the target autonomous region N based on the observations made by the AS consortium u. This refers to the illegal declaration made by the AS consortium u regarding the target autonomous region N; express The service domain, that is, the service domain described by AS consortium u. The set of all other ASs that can be affected, where ρ represents the preset second coefficient, P A,f express For any target AS in the array, W(P) A,f Then it means P A,f The weight of , j represents the number of attack actions on the target autonomous region N.
[0101] Furthermore, based on the accumulated legal declaration utility value and accumulated illegal declaration utility value obtained from the above calculations, the declaration reputation of the AS alliance implementing the observation for the target AS assessment can be calculated, that is, the declaration reputation of the AS alliance u for the target autonomous region N assessment.
[0102] Specifically, the following formula can be used for calculation:
[0103]
[0104] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. u,A (N) represents the declared reputation of the AS consortium u for the target autonomous region N within an evaluation period.
[0105] In this embodiment, based on a defined AS alliance that implements observations, the routing reputation of each target AS can be calculated using the accumulated legitimate routing utility value and the accumulated illegitimate routing utility value.
[0106] Specifically, the legal routing utility value for the target AS refers to the value assigned to the legal routing forwarding performed by the target AS. Specifically, when the AS alliance that is determined to perform the observation observes the target AS performing a legal routing forwarding, a legal routing forwarding utility value corresponding to the legal routing forwarding behavior and corresponding to the AS alliance that is performing the observation is generated for the target AS.
[0107] Furthermore, the illegal routing utility value of the target AS refers to the value assigned to the illegal routing forwarding performed by the target AS. Specifically, when the AS alliance that is determined to perform the observation observes the target AS performing an illegal routing forwarding, an illegal routing forwarding utility value corresponding to the illegal routing forwarding behavior and the AS alliance that performs the observation is generated for the target AS.
[0108] It can be seen that the utility values of legitimate routing and forwarding and illegal routing and forwarding are corresponding. That is to say, when describing the aforementioned two utility values, it is necessary to clarify that the utility value is the value evaluated by the AS alliance that implements the observation for its corresponding specific target AS. However, the above utility values evaluated by different AS alliances that implement the observation for the same target AS are different.
[0109] Furthermore, the cumulative values of multiple legitimate routing utility values and illegal routing utility values assessed by the AS consortium implementing the observations for the target AS are determined.
[0110] Specifically, the cumulative legitimate route forwarding utility value of the AS alliance implementing the observation for the target AS is expressed by the following formula:
[0111]
[0112] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. This represents the accumulated legitimate routing utility value of the target autonomous system N, and this legitimate routing utility value is an evaluation of the target autonomous system N based on the observations of the AS alliance u. This refers to the legitimate route forwarding observed by AS alliance u for the target autonomous region N; express The service domain, that is, the service domain described by AS consortium u. The set of all other ASs that can be affected, where ω represents the preset third coefficient, P A,t express For any target AS in the array, W(P) E,t Then it means P E,t The weight.
[0113] Furthermore, the cumulative illegal routing forwarding utility value of the AS alliance implementing the observation for the target AS is expressed by the following formula:
[0114]
[0115] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. This represents the accumulated illegal routing utility value of the target autonomous system N, and this illegal routing utility value is an evaluation of the target autonomous system N based on the observations of the AS alliance u. This refers to the illegal route forwarding observed by AS consortium u in the target autonomous region N; express The service domain, that is, the service domain described by AS consortium u. The set of all other ASs that can be affected, where λ represents the preset fourth coefficient, P E,f express For any target AS in the array, W(P) E,f Then it means P E,f The weight of λ is denoted by j, which represents the number of attack actions of the target autonomous system N. D(N) represents the penalty coefficient for forwarding illegal routes. When the target autonomous system N is the initiator of the path hijacking behavior, λ = 1. If the target autonomous system N is not the initiator of the path hijacking behavior, λ = 0. Furthermore, the value of D(N) can be set according to the number of hops between the autonomous system that is launching the attack and the target autonomous system N. For example, the closer the number of hops between the autonomous system that is launching the attack and the target autonomous system N is, the larger D(N) will be.
[0116] Furthermore, based on the accumulated legitimate routing utility value and the accumulated illegal routing utility value calculated above, the routing reputation of the AS alliance that implemented the observation for the target AS can be calculated, that is, the routing reputation of AS alliance u for the target autonomous system N.
[0117] Specifically, the following formula can be used for calculation:
[0118]
[0119] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. u,E (N) represents the routing reputation of the target autonomous system N as evaluated by the AS alliance u within an evaluation period.
[0120] It should be noted that there is no specific order for calculating the advertised reputation and the routing reputation. The calculation order of the two in this embodiment is merely exemplary. In some other embodiments, the routing reputation can be calculated first, and then the advertised reputation can be calculated.
[0121] Step S103: For each target autonomous system, using the declared reputation and routing reputation of each corresponding autonomous system alliance, calculate the local reputation of each corresponding autonomous system alliance for the target autonomous system in the current evaluation period.
[0122] In the embodiments of this application, the local reputation of the target AS can be calculated based on the declared reputation and routing reputation determined above.
[0123] Based on the aforementioned steps, it can be seen that since the declared reputation and the routing reputation are corresponding, the reputation value calculated based on the declared reputation and the routing reputation is also corresponding. In other words, the calculated reputation value is based on the evaluation of the AS alliance that implements the observation for its corresponding specific target AS. However, the reputation value evaluated by other different AS alliances that implement the observation for the same target AS is different. Based on this, the reputation value is referred to as local reputation in this embodiment.
[0124] Specifically, local credit can be calculated using the following formula:
[0125] T u (N)=αT u,A (N)+βT u,E (N)
[0126] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. u (N) represents the local reputation of the AS consortium u that performs the observations on the target autonomous region N within an evaluation period, α represents the preset first adjustable parameter, β represents the preset second adjustable parameter, and α and β satisfy the following: α > 0, β > 0, α + β = 1.
[0127] Step S104: For each Autonomous Region Alliance, determine the observation weight of the Autonomous Region Alliance based on its observations of all corresponding target Autonomous Regions; for each target Autonomous Region, utilize the local reputation of the target Autonomous Region by all corresponding Autonomous Region Alliances and determine the first global reputation independently evaluated in the current period based on the observation weight of each; use the first global reputation and combine it with the first global reputation of the target Autonomous Region evaluated in the previous period to calculate the second global reputation of the target Autonomous Region in the current evaluation period.
[0128] In the embodiments of this application, as described in step S103 above, the local reputation of the target AS calculated above corresponds only to one AS alliance among multiple AS alliances that implement observations. Therefore, it is also necessary to calculate the global reputation of the target AS based on the local reputation, that is, to integrate the evaluations of the target AS by all AS alliances that implement observations.
[0129] In this embodiment, the calculation of global reputation takes into account the independent assessments performed in the current period, which are referred to as the first global reputation in this embodiment. The first global reputation is further combined with the assessment results performed in the previous period to obtain the second global reputation.
[0130] Specifically, firstly, the first global reputation is calculated according to the formula shown below:
[0131]
[0132] Wherein, the superscript u is a pre-configured number for the AS consortium. In this embodiment, the superscript u represents the specified AS consortium. g (N) represents the first global reputation. It can be seen that the first global reputation describes the global reputation calculated in any period without involving the evaluation results of other periods.
[0133] Furthermore, in the above formula for calculating the first global reputation, W u (N) represents the observation weight of the AS consortium u towards the target autonomous system N, which can be calculated using the following formula:
[0134]
[0135] Furthermore, based on the first global reputation determined above, the second global reputation can be calculated using the following formula:
[0136]
[0137] Among them, GT k (N) represents the second global reputation in the current k-th evaluation period. This represents the first global reputation of the target autonomous region N at the current k-th evaluation period, σ represents the preset time decay coefficient, and GT k-1 (N) represents the second global reputation determined in the (k-1)th evaluation period.
[0138] It can be seen that the results of the second global reputation assessment in the previous period are used to determine the assessment results of the second global reputation in the next period through an iterative approach. It is evident that this method gives the second global reputation a certain degree of time forgetting, and at the beginning of each assessment period, the number of recent attack behaviors of the target AS is decremented by 1 for calculation.
[0139] Step S105: Based on two preset autonomous systems, determine multiple initial routes between the two autonomous systems. Using a preset reputation threshold, select multiple candidate routes from the multiple initial routes. For each candidate route, calculate the route reputation value using the second global reputation of each autonomous system in the candidate route. Based on the route reputation value of each candidate route, determine the target route between the two autonomous systems.
[0140] In the embodiments of this application, inter-domain routing can be selected based on the second global reputation value of the target AS determined above.
[0141] Specifically, for any two ASs, there are multiple optional inter-domain routes. In this embodiment, in the initial stage of filtering, all optional inter-domain routes between the two ASs are referred to as initial routes.
[0142] Furthermore, such as Figure 2 As shown, step S201 is executed to verify the mechanism.
[0143] Specifically, determine whether there is a security mechanism to verify the legitimacy of the route. If any security mechanism exists, proceed to step S202; if no security mechanism exists, proceed directly to step S203.
[0144] Further, in step S202, verification and filtering are performed.
[0145] Specifically, all available initial routes are input into the aforementioned security mechanism for verification, and any illegal routes discovered are excluded from the initial routes. The initially filtered initial routes are then allowed to continue executing step S203.
[0146] Further, in step S203, the target AS is determined.
[0147] Specifically, for all initial routes entering step S203, the second global reputation value of each target AS in each initial route is determined.
[0148] Furthermore, for each initial route, the second global reputation value of each target AS is compared with a pre-set reputation threshold.
[0149] Further, step S204 is performed to determine candidate routes.
[0150] Specifically, if the second global reputation value of any target AS in the initial route is less than a preset reputation threshold, the initial route will be filtered out.
[0151] If the second global reputation value of any target AS in the initial route is greater than or equal to the preset reputation threshold, then the initial route is selected as a candidate route.
[0152] Further, step S205 is performed to calculate and sort the route reputation values.
[0153] Specifically, for each candidate route, the second global reputation values of each target AS are combined to obtain the route reputation value of the candidate route.
[0154] The following formula can be used for calculation:
[0155]
[0156] Among them, T r N represents the route reputation value of candidate route r. i Let k represent the i-th target AS on candidate route r. i This indicates the preset N. i The weight.
[0157] Further, step S205 is performed to calculate and sort the route reputation values.
[0158] Specifically, based on the route reputation values of each candidate route determined above, the candidate routes are sorted in descending order of their route reputation values.
[0159] Further, proceed to step S206 to determine the target route.
[0160] Specifically, determine the highest route reputation value and set the difference threshold X.
[0161] Furthermore, the difference between each route reputation value and the highest route reputation value is calculated, and route reputation values with differences exceeding the difference threshold X are filtered out.
[0162] Furthermore, if only one candidate route remains after being filtered out, that candidate route will be used as the target route; if there are multiple candidate routes that have not been filtered out, other route filtering strategies can be adopted to select one target route.
[0163] It can be seen that, based on the AS alliance's observations of other autonomous systems and taking into account the target AS's advertised reputation and routing reputation, local reputation is calculated to subdivide the impact of different behaviors of the target AS. By combining the observations of multiple AS alliances corresponding to the target AS, the second global reputation value under the overall situation is determined. The second global reputation value is determined by taking into account the first global reputation value assessment conducted independently of other periods in each period, as well as the assessment results of other periods. This makes the second global reputation value take into account factors such as time decay, thus obtaining a more accurate assessment result and improving the accuracy of route selection.
[0164] It should be noted that the method of the embodiments of this application can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied in a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of the embodiments of this application, and the multiple devices will interact with each other to complete the method described.
[0165] It should be noted that the above description describes some embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0166] Based on the same inventive concept, corresponding to any of the above embodiments, the embodiments of this application also provide an inter-domain routing selection device based on reputation assessment.
[0167] refer to Figure 3 The reputation-based inter-domain routing device includes: a preprocessing module 301, a reputation declaration and routing forwarding reputation calculation module 302, a local reputation calculation module 303, a second global reputation calculation module 304, and a target route determination module 305.
[0168] The preprocessing module 301 is configured to, within the current evaluation period, determine multiple other autonomous systems that can be observed by each of the multiple autonomous system alliances in the communication network, and use them as multiple target autonomous systems corresponding to the autonomous system alliance.
[0169] The declared reputation and routing reputation calculation module 302 is configured to, for each target autonomous region, calculate the declared reputation of the target autonomous region with respect to each of the corresponding autonomous region associations in the current evaluation period; and calculate the routing reputation of the target autonomous region with respect to each of the corresponding autonomous region associations in the current evaluation period.
[0170] The local reputation calculation module 303 is configured to, for each target autonomous region, calculate the local reputation of each corresponding autonomous region alliance for the target autonomous region within the current evaluation period using the declared reputation and the routing reputation of each corresponding autonomous region alliance.
[0171] The second global reputation calculation module 304 is configured to: for each autonomous region alliance, determine the observation weight of the autonomous region alliance based on the observations of the autonomous region alliance on all corresponding target autonomous regions; for each target autonomous region, use the local reputation of the target autonomous region by all corresponding autonomous region alliances and determine the first global reputation independently evaluated in the current period based on the observation weights of each; and use the first global reputation, combined with the first global reputation of the target autonomous region evaluated in the previous period, to calculate the second global reputation of the target autonomous region in the current evaluation period.
[0172] The target route determination module 305 is configured to determine multiple initial routes between two preset autonomous systems based on two preset autonomous systems, filter multiple candidate routes from the multiple initial routes using a preset reputation threshold, calculate a route reputation value for each candidate route using the second global reputation of each autonomous system in the candidate route, and determine the target route between the two autonomous systems based on the route reputation value of each candidate route.
[0173] For ease of description, the above apparatus is described in terms of its functions, divided into various modules. Of course, in implementing the embodiments of this application, the functions of each module can be implemented in one or more software and / or hardware.
[0174] The apparatus of the above embodiments is used to implement the corresponding reputation-based inter-domain routing method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0175] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, embodiments of this application also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the inter-domain routing method based on reputation assessment as described in any of the above embodiments.
[0176] Figure 4 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.
[0177] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.
[0178] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this application are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0179] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.
[0180] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0181] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.
[0182] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this application, and not necessarily all the components shown in the figures.
[0183] The apparatus of the above embodiments is used to implement the corresponding reputation-based inter-domain routing method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0184] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the reputation-based inter-domain routing method as described in any of the above embodiments.
[0185] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0186] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the inter-domain routing method based on reputation assessment as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0187] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this application (including the claims) is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this application as described above, which are not provided in detail for the sake of brevity.
[0188] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this application, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this application, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this application will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of this application, it will be apparent to those skilled in the art that the embodiments of this application can be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0189] Although this application has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0190] The embodiments of this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this application should be included within the protection scope of this application.
Claims
1. A reputation-based inter-domain routing method, characterized in that, include: Within the current evaluation period, multiple other autonomous systems that can be observed by each of the multiple autonomous system alliances in the communication network are identified and used as multiple target autonomous systems corresponding to the autonomous system alliance. Each autonomous system alliance contains multiple autonomous system nodes, and the autonomous system nodes can cooperate with each other to complete the pre-specified tasks. For each target autonomous region (AUR), the legal declaration utility value and illegal declaration utility value observed by the corresponding AUR alliance are determined. Using the accumulated legal declaration utility value and accumulated illegal declaration utility value, the declaration reputation of the target AUR with respect to the corresponding AUR alliance is calculated using the following formula: Where N represents the target autonomous region being observed, and u represents the autonomous region alliance that performs the observation of the target autonomous region. This represents the declared reputation of the autonomous domain alliance u towards the target autonomous domain N. This represents the accumulated legal declaration utility value of the target autonomous region N. This represents the accumulated illegal declaration utility value of the target autonomous system N; and determines the legal routing utility value and illegal routing utility value observed by the corresponding autonomous system association. Using the accumulated legal routing utility value and the accumulated illegal routing utility value, the routing reputation of the target autonomous system with respect to the corresponding autonomous system association is calculated using the following formula: in, This represents the routing and forwarding reputation of the autonomous region association u towards the target autonomous region N. This represents the accumulated legitimate routing forwarding utility value for the target autonomous system N. This represents the accumulated illegal routing forwarding utility value for the target autonomous system N; For each target autonomous system, the local reputation of each corresponding autonomous system alliance to that target autonomous system within the current evaluation period is calculated using the declared reputation and routing reputation of each corresponding autonomous system alliance; wherein, the local reputation can be calculated according to the following formula: Here, the superscript 'u' is a pre-configured number for the AS consortium, used to represent the specified AS consortium. This represents the local reputation of the AS consortium u that conducted the observations for the target autonomous region N within an evaluation period. This indicates the first preset adjustable parameter. This indicates the preset second adjustable parameter, and and The following conditions must be met: ; For each target autonomous region, determine the autonomous region alliance that will observe the target autonomous region; The observation weights for the target autonomous region are determined using the formula shown below: in, This represents the observation weights of the autonomous region consortium u to the target autonomous region N; The legal declaration of the target autonomous region N as observed by the autonomous region consortium u; The illegal declaration observed by the autonomous region consortium u in the target autonomous region N; This refers to the legal route forwarding observed by the autonomous region alliance u for the target autonomous region N; This refers to the illegal route forwarding observed by the autonomous region alliance u in the target autonomous region N; express At least one target autonomous region is affected; express At least one target autonomous region is affected; express At least one target autonomous region is affected; express At least one target autonomous region is affected; express Any target autonomous region in the, express The weights; express Any target autonomous region in the, express The weights; express Any target autonomous region in the, express The weights; express Any target autonomous region in the, express The weights are determined as follows: For each target autonomous region, the local reputation of the target autonomous region is calculated using all the corresponding autonomous region alliances, and based on the respective observation weights, the local reputations of the target autonomous region are weighted and aggregated according to the following formula to obtain the first global reputation: in, Indicates first overall reputation, This represents the local reputation of the autonomous region alliance u on the target autonomous region N, where the first global reputation is calculated independently within the current period; Based on the assessment of the target autonomous region in the previous assessment period, and according to the set time decay coefficient, the second global reputation for the current assessment period is determined using the following formula: in, This represents the second global reputation in the current k-th evaluation period. This represents the first global reputation of the target autonomous region N at the current k-th evaluation period. This represents the preset time decay coefficient. This represents the second global reputation determined in the (k-1)th evaluation period; Based on two preset autonomous systems, multiple initial routes between the two autonomous systems are determined. Using a preset reputation threshold, multiple candidate routes are selected from the multiple initial routes. For each candidate route, a route reputation value is calculated using the second global reputation of each autonomous system in the candidate route. Based on the route reputation values of each candidate route, a target route between the two autonomous systems is determined.
2. The method according to claim 1, characterized in that, The step of filtering multiple candidate routes from the multiple initial routes includes: For each of the initial routes, perform the following operation: Determine the second global reputation value for each autonomous system in the initial route; Determine whether the second global reputation value of each autonomous region is lower than the preset reputation threshold; If the second global reputation value of any autonomous system in the initial route is greater than or equal to the preset reputation threshold, then the initial route is selected as the candidate route.
3. The method according to claim 1, characterized in that, The step of calculating a route reputation value using the second global reputation of each autonomous system in the candidate routes, and determining the target route between the two autonomous systems based on the route reputation values of each candidate route, includes: The route reputation value for each candidate route is calculated using the following formula: in, This represents the route reputation value of candidate route r. This represents the i-th target autonomous system on candidate route r. This indicates a preset. The weights; Sort all the candidate routes in descending order of their respective route reputation values; Determine the difference between the highest route reputation value and the reputation values of all other routes; If the difference exceeds a predetermined difference threshold, the candidate route corresponding to the route reputation value is excluded. Using a preset route selection mechanism, a target route is determined from the candidate routes that have never been excluded.
4. An inter-domain routing device based on reputation assessment, comprising: The module includes a preprocessing module, a reputation declaration and routing forwarding reputation calculation module, a local reputation calculation module, a second global reputation calculation module, and a target route determination module. The preprocessing module is configured to, within the current evaluation period, identify multiple other autonomous systems that can be observed by each of the multiple autonomous system alliances in the communication network, and use them as multiple target autonomous systems corresponding to the autonomous system alliance. The declared reputation and routing reputation calculation module is configured to, for each target autonomous region (AUR), determine the legal and illegal declared utility values observed by the corresponding AUR alliance, and calculate the declared reputation of the target AUR with respect to the corresponding AUR alliance using the accumulated legal and illegal declared utility values, according to the following formula: Where N represents the target autonomous region being observed, and u represents the autonomous region alliance that performs the observation of the target autonomous region. This represents the declared reputation of the autonomous domain alliance u towards the target autonomous domain N. This represents the accumulated legal declaration utility value of the target autonomous region N. This represents the accumulated illegal declaration utility value of the target autonomous system N; and determines the legal routing utility value and illegal routing utility value observed by the corresponding autonomous system association. Using the accumulated legal routing utility value and the accumulated illegal routing utility value, the routing reputation of the target autonomous system with respect to the corresponding autonomous system association is calculated using the following formula: in, This represents the routing and forwarding reputation of the autonomous region association u towards the target autonomous region N. This represents the accumulated legitimate routing forwarding utility value for the target autonomous system N. This represents the accumulated illegal routing forwarding utility value for the target autonomous system N; The local reputation calculation module is configured to, for each target autonomous system, calculate the local reputation of each corresponding autonomous system alliance towards the target autonomous system within the current evaluation period, using the declared reputation and routing reputation of each corresponding autonomous system alliance; wherein, the local reputation can be calculated according to the following formula: Here, the superscript 'u' is a pre-configured number for the AS consortium, used to represent the specified AS consortium. This represents the local reputation of the AS consortium u that conducted the observations for the target autonomous region N within an evaluation period. This indicates the first preset adjustable parameter. This indicates the preset second adjustable parameter, and and The following conditions must be met: ; The second global reputation calculation module is configured to, for each of the target autonomous regions, determine the autonomous region alliance that observes the target autonomous region; The observation weights for the target autonomous region are determined using the formula shown below: in, This represents the observation weight of the autonomous region consortium u towards the target autonomous region N; The legal declaration of the target autonomous region N as observed by the autonomous region consortium u; The illegal declaration observed by the autonomous region consortium u in the target autonomous region N; This refers to the legal route forwarding observed by the autonomous region alliance u for the target autonomous region N; This refers to the illegal route forwarding observed by the autonomous region alliance u in the target autonomous region N; express At least one target autonomous region is affected; express At least one target autonomous region is affected; express At least one target autonomous region is affected; express At least one target autonomous region is affected; express Any target autonomous region in the, express The weights; express Any target autonomous region in the, express The weights; express Any target autonomous region in the, express The weights; express Any target autonomous region in the, express The weights; for each target autonomous region, the local reputation of the target autonomous region is used by all the corresponding autonomous region alliances, and according to the respective observation weights, For the target autonomous region, using the determined observation weights, the local reputations of each entity in the target autonomous region are weighted and aggregated according to the following formula to obtain the first global reputation: in, Indicates first overall reputation, This represents the local reputation of the autonomous region alliance u on the target autonomous region N, where the first global reputation is calculated independently within the current period; Based on the assessment of the target autonomous region in the previous assessment period, and according to the set time decay coefficient, the second global reputation for the current assessment period is determined using the following formula: in, This represents the second global reputation in the current k-th evaluation period. This represents the first global reputation of the target autonomous region N at the current k-th evaluation period. This represents the preset time decay coefficient. This represents the second global reputation determined in the (k-1)th evaluation period; The target route determination module is configured to determine multiple initial routes between two preset autonomous systems, filter multiple candidate routes from the multiple initial routes using a preset reputation threshold, calculate a route reputation value for each candidate route using the second global reputation of each autonomous system in the candidate route, and determine the target route between the two autonomous systems based on the route reputation value of each candidate route.
5. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 2.
6. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions for causing a computer to perform the method according to any one of claims 1 to 2.
Citation Information
Patent Citations
Point-to-point network prestige management method based on market model
CN101321161A
Autonomous inter-domain routing security assessment method and device
CN110061918A