Route leak determination method, apparatus, device, and storage medium
By publishing the routing information of AS nodes on the blockchain and detecting AS paths hop by hop, the problem of low accuracy in determining route leakage in existing technologies is solved, achieving highly accurate and privacy-preserving route leakage detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2021-09-27
- Publication Date
- 2026-05-08
AI Technical Summary
Existing technologies have low accuracy in identifying route leaks because detection devices cannot collect all historical routing information, especially confidential routing information, leading to incorrect inferences about business relationships.
By publishing the routing information of each AS node on the blockchain, the routing information in the AS path is used for detection. The routing information of each AS node is detected hop by hop, a routing detection identifier is generated, and the routing leakage path is determined.
It improves the accuracy of route leakage determination, protects the privacy of AS's economic decision-making, and ensures the accuracy and security of routing information.
Smart Images

Figure CN115883114B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, device and storage medium for determining route leakage. Background Technology
[0002] Border Gateway Protocol (BGP) is a dynamic routing protocol used between Autonomous Systems (AS) to ensure basic communication capabilities between them. ASs typically have various business relationships, and their routing strategies vary depending on these relationships. However, if an AS violates its own routing strategy due to misconfiguration or malicious behavior, forwarding received routing information to ASs that shouldn't receive it, it can lead to the leakage of routes that shouldn't be advertised, causing network congestion, route hijacking, and traffic drop, among other security issues.
[0003] Currently, detection devices are typically used to determine whether route leakage has occurred in a network. For example, detection devices collect historical routing information published by each AS. When an AS publishes routing information, the detection device infers the business relationships between that AS and other ASs based on the historical routing information published by that AS, and then determines whether route leakage has occurred based on the routing and forwarding policy of that AS.
[0004] However, not all historical routing information can be collected by the detection device (for example, some routing information that needs to be kept confidential will not be collected by the detection device). Therefore, the above method may sometimes lead to errors in inferring business relationships between ASs, resulting in a low accuracy rate in determining route leaks. Summary of the Invention
[0005] This application provides a method, apparatus, device, and storage medium for determining route leakage, which can effectively improve the accuracy of route leakage determination. The technical solution is as follows:
[0006] Firstly, a method for determining route leakage is provided, executed by the first AS node, the method comprising:
[0007] Receive Border Gateway Protocol (BGP) update messages published by the second AS node;
[0008] Based on the BGP update message, obtain the AS path, which indicates the multiple AS nodes traversed from the second AS node to the first AS node;
[0009] Obtain the routing information published to the blockchain by the multiple AS nodes in the AS path. The routing information includes the adjacent AS nodes of the corresponding AS node.
[0010] Based on the routing information published to the blockchain by these multiple AS nodes, the AS path is detected to obtain routing detection information, which indicates whether the AS path is a path where routing leakage has occurred.
[0011] In this method, when the first AS node receives a BGP update message published by the second AS node, it obtains the AS path from the BGP update message. Then, using the routing information published to the blockchain by multiple AS nodes along that AS path, it detects the AS path and promptly determines whether a route leak has occurred. In this process, the routing information of multiple AS nodes is publicly disclosed through the blockchain, possessing the characteristics of immutability and trustworthiness, thus ensuring the accuracy of the routing information and improving the accuracy of route leak detection. Moreover, this routing information does not disclose the business relationships between ASes, thus protecting the privacy of AS economic decisions and making it easily adoptable. When most ASes in the network use this method to determine route leaks, the accuracy of route leak detection can be greatly improved.
[0012] In some embodiments, the routing information further includes at least one target routing prefix for the corresponding AS node, and obtaining the routing information published to the blockchain by the plurality of AS nodes in the AS path includes:
[0013] Based on the BGP update message, at least one first routing prefix is obtained, which is the Internet Protocol IP prefix announced by the second AS node;
[0014] Based on the at least one first routing prefix, obtain the routing information published on the blockchain by the multiple AS nodes, wherein the at least one first routing prefix matches the at least one target routing prefix.
[0015] By including at least one target route prefix in the routing information, the determination of route leakage at the AS level can be refined to the route prefix level. When the first AS node detects whether the AS path is a path where a route leakage has occurred, it can ensure that the path corresponding to the route prefix that conforms to the routing forwarding policy is guaranteed to have communication, thereby effectively improving the accuracy of route leakage determination.
[0016] In some embodiments, the routing information published to the blockchain by the plurality of AS nodes is used to detect the AS path and obtain routing detection information, including:
[0017] Based on the order of the multiple AS nodes indicated by the AS path, the routing information of each AS node is detected hop-by-hop to obtain the routing detection information.
[0018] By using hop-by-hop detection, it was determined whether an AS path was a path where route leakage had occurred. In this process, it was determined whether each AS node met the routing forwarding conditions, thereby integrating the situation of the entire AS path to obtain route leakage detection information, which effectively improved the accuracy of route leakage determination.
[0019] In some embodiments, the routing information of each AS node is detected hop-by-hop based on the order of the plurality of AS nodes indicated by the AS path to obtain the routing detection information, including:
[0020] Based on whether the neighboring nodes indicated by the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path, a route detection identifier is generated for each AS node. The route detection identifier indicates whether the corresponding AS node meets the route forwarding conditions.
[0021] The route detection information is obtained based on the route detection identifier of each AS node.
[0022] In some embodiments, generating a route detection identifier for each AS node based on whether the neighboring nodes indicated by the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path includes:
[0023] For any AS node among the plurality of AS nodes, if the neighboring node indicated by the routing information of any AS node is the same as the neighboring node of any AS node in the AS path, a first route detection identifier is generated for any AS node, and the first route detection identifier indicates that any AS node meets the route forwarding condition.
[0024] If the neighboring node indicated by the routing information of any AS node is different from the neighboring node of any AS node in the AS path, a second route detection identifier is generated for any AS node, and the second route detection identifier indicates that any AS node does not meet the route forwarding condition.
[0025] If routing information for any AS node is not obtained, a third routing detection identifier for that AS node is generated, indicating that routing information for that AS node has not been obtained.
[0026] By using hop-by-hop detection, a route detection identifier is generated for each AS node. There are multiple types of route detection identifiers, which facilitates the subsequent targeted integration of the detection results of each hop in the AS path to obtain the route detection information of the AS path.
[0027] In some embodiments, the route detection information obtained based on the route detection identifier of each AS node includes:
[0028] If neither the first target AS node nor the second target AS node exists among the multiple AS nodes, first route detection information is generated. The route detection identifier of the first target AS node is the second route detection identifier, and the route detection identifier of the second target AS node is the third route detection identifier. The first route detection information indicates that the AS path is a safe path.
[0029] If the first target AS node exists among the multiple ASs, generate second route detection information, which indicates that the AS path is the path where route leakage has occurred.
[0030] If the second target AS node exists among the multiple ASs, but the first target AS node does not exist, third route detection information is generated, which indicates that the AS path is a path with unknown security.
[0031] In some embodiments, the method further includes:
[0032] If the route detection information indicates that the AS path is a path where a route leak has occurred, discard the BGP update message.
[0033] This process can also be understood as filtering the AS path to prevent subsequent traffic from flooding into AS nodes that have experienced route leaks, thereby improving the security of inter-AS communication.
[0034] In some embodiments, the method further includes:
[0035] If the route detection information indicates that the AS path is a path with unknown security, the AS path is identified as a candidate path and added to the routing table of the first AS node.
[0036] This process can also be understood as reducing the priority of the AS path, prioritizing the selection of a safe AS path in subsequent traffic transmission, thereby maximizing the reasonable balance between network reachability and security.
[0037] In some embodiments, the method further includes:
[0038] The routing information of the first AS node is published to the blockchain;
[0039] The routing information of the first AS node includes: the identifier of the first AS node, at least one second routing prefix of the first AS node, and the neighboring nodes of the first AS node, wherein the second routing prefix is the IP prefix advertised by the first AS node.
[0040] Secondly, a route leakage determination device is provided, the device comprising:
[0041] The receiving module is used to receive Border Gateway Protocol (BGP) update messages published by the second AS node.
[0042] The first acquisition module is used to acquire the AS path based on the BGP update message. The AS path indicates the multiple AS nodes traversed from the second AS node to the first AS node.
[0043] The second acquisition module is used to acquire the routing information published to the blockchain by the multiple AS nodes in the AS path, and the routing information includes the adjacent AS nodes of the corresponding AS node.
[0044] The detection module is used to detect the AS path based on the routing information published to the blockchain by the multiple AS nodes, and obtain routing detection information, which indicates whether the AS path is a path where routing leakage has occurred.
[0045] In some embodiments, the routing information further includes at least one target routing prefix of the corresponding AS node, and the second acquisition module is configured to:
[0046] Based on the BGP update message, at least one first routing prefix is obtained, which is the Internet Protocol IP prefix announced by the second AS node;
[0047] Based on the at least one first routing prefix, obtain the routing information published on the blockchain by the multiple AS nodes, wherein the at least one first routing prefix matches the at least one target routing prefix.
[0048] In some embodiments, the detection module is configured to:
[0049] Based on the order of the multiple AS nodes indicated by the AS path, the routing information of each AS node is detected hop-by-hop to obtain the routing detection information.
[0050] In some embodiments, the detection module is configured to:
[0051] Based on whether the neighboring nodes indicated by the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path, a route detection identifier is generated for each AS node. The route detection identifier indicates whether the corresponding AS node meets the route forwarding conditions.
[0052] The route detection information is obtained based on the route detection identifier of each AS node.
[0053] In some embodiments, the detection module is configured to:
[0054] For any AS node among the plurality of AS nodes, if the neighboring node indicated by the routing information of any AS node is the same as the neighboring node of any AS node in the AS path, a first route detection identifier is generated for any AS node, and the first route detection identifier indicates that any AS node meets the route forwarding condition.
[0055] If the neighboring node indicated by the routing information of any AS node is different from the neighboring node of any AS node in the AS path, a second route detection identifier is generated for any AS node, and the second route detection identifier indicates that any AS node does not meet the route forwarding condition.
[0056] If routing information for any AS node is not obtained, a third routing detection identifier for that AS node is generated, indicating that routing information for that AS node has not been obtained.
[0057] In some embodiments, the detection module is configured to:
[0058] If neither the first target AS node nor the second target AS node exists among the multiple AS nodes, first route detection information is generated. The route detection identifier of the first target AS node is the second route detection identifier, and the route detection identifier of the second target AS node is the third route detection identifier. The first route detection information indicates that the AS path is a safe path.
[0059] If the first target AS node exists among the multiple ASs, generate second route detection information, which indicates that the AS path is the path where route leakage has occurred.
[0060] If the second target AS node exists among the multiple ASs, but the first target AS node does not exist, third route detection information is generated, which indicates that the AS path is a path with unknown security.
[0061] In some embodiments, the device further includes:
[0062] The discard module is used to discard the BGP update message if the route detection information indicates that the AS path is a path where a route leak has occurred.
[0063] In some embodiments, the device further includes:
[0064] Add a module to identify the AS path as an alternative path and add it to the routing table of the first AS node if the route detection information indicates that the AS path is a path with unknown security.
[0065] In some embodiments, the device further includes:
[0066] The publishing module is used to publish the routing information of the first AS node to the blockchain;
[0067] The routing information of the first AS node includes: the identifier of the first AS node, at least one second routing prefix of the first AS node, and the neighboring nodes of the first AS node, wherein the second routing prefix is the IP prefix advertised by the first AS node.
[0068] Thirdly, this application provides a network device including a memory and a processor. The memory stores a set of computer instructions, and the processor executes the set of computer instructions stored in the memory to cause the network device to perform the routing leakage determination method provided in the first aspect or any possible implementation thereof.
[0069] Fourthly, this application provides a computer-readable storage medium storing computer program code. When the computer program code is executed by a computing device, the computing device executes the route leakage determination method provided in the first aspect or any possible implementation thereof. The storage medium includes, but is not limited to, volatile memory, such as random access memory, and non-volatile memory, such as flash memory, hard disk drive (HDD), and solid-state drive (SSD).
[0070] Fifthly, this application provides a computer program product comprising computer program code. When the computer program code is executed by a network device, the network device executes the route leakage determination method provided in the first aspect or any possible implementation thereof. The computer program product can be a software installation package. When the route leakage determination method provided in the first aspect or any possible implementation thereof is required, the computer program product can be downloaded and executed on the network device. Attached Figure Description
[0071] Figure 1 This is a schematic diagram of a valley-free forwarding strategy provided in an embodiment of this application;
[0072] Figure 2 This is a schematic diagram of the implementation environment of a route leakage determination method provided in an embodiment of this application;
[0073] Figure 3 This is a schematic diagram of the architecture of a database system provided in an embodiment of this application;
[0074] Figure 4 This is a schematic diagram of the structure of a network device provided in an embodiment of this application;
[0075] Figure 5 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application;
[0076] Figure 6 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application;
[0077] Figure 7 This is a schematic diagram of routing information provided in an embodiment of this application;
[0078] Figure 8 This is a schematic diagram illustrating an application scenario of a route leakage determination method provided in an embodiment of this application;
[0079] Figure 9 This is a schematic diagram illustrating an application scenario of another route leakage determination method provided in this application embodiment;
[0080] Figure 10 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application;
[0081] Figure 11 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application;
[0082] Figure 12 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application;
[0083] Figure 13 This is a schematic diagram of a route leakage determination device provided in an embodiment of this application. Detailed Implementation
[0084] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0085] Before introducing the technical solutions provided by the embodiments of the present invention, the key terms involved in the present invention will be explained below.
[0086] An Autonomous System (AS) is a small unit in the Internet that has the authority to independently decide which routing protocol to use within the system. This unit can be a simple network or a group of networks controlled by one or more ordinary network administrators; it is a single, manageable network unit (such as a university, an enterprise, or a company). In some embodiments, an AS is also referred to as a routing domain. In some embodiments, an AS possesses a globally unique Autonomous System Number (ASN).
[0087] Border Gateway Protocol (BGP) is a dynamic routing protocol used between Autonomous Systems (AS). It ensures basic communication capabilities between ASs and enables loop-free inter-domain routing. When two ASs need to exchange routing information, each AS needs to designate a node running BGP to exchange routing information with other ASs on its behalf. In some embodiments, this node is typically a router, and the router that uses BGP to exchange information between two ASs is also called a border gateway or border router.
[0088] Valley-free policy is a routing and forwarding strategy followed by ASs based on their different business relationships. Typically, business relationships between ASs are divided into four types: customer-to-provider (C2P), peer-to-peer (P2P), sibling-to-sibling (S2S), and hybrid relationships. (See illustration for reference.) Figure 1 , Figure 1 This is a schematic diagram of a valley-free forwarding strategy provided in an embodiment of this application. For example... Figure 1 As shown, customers pay network access fees to providers, and peers also sign corresponding commercial agreements based on the amount of traffic forwarded. However, the AS (Application Server) neither provides forwarding services for free nor actively pays to help its neighbors forward traffic. Therefore, the AS will not forward BGP routes learned from providers or peers to other providers or peers; this route forwarding strategy is called valley-free forwarding.
[0089] The Gao-Rexford Guidelines are a set of guidelines for setting routing policies, proposed by Gao and Rexford, to ensure network routing security. These guidelines are also based on the business relationships between ASes.
[0090] Blockchain is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. It possesses properties such as transparency, trustworthiness, tamper-proofness, and traceability. Essentially, a blockchain is a decentralized database, a chain of data blocks linked using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. In other words, blockchain technology is a decentralized architecture and computing paradigm that utilizes a block-chain data structure to verify and store data, distributed node consensus algorithms to generate and update data, cryptography to ensure the security of data transmission and access, and smart contracts composed of automated script code to program and manipulate data.
[0091] A consensus mechanism is an algorithm for achieving distributed consensus on blockchain transactions. In this application embodiment, users can choose a suitable consensus algorithm based on their actual business scenario. Such consensus algorithms include, but are not limited to: Proof of Work (PoW), Proof of Stake (PoS), Delegated Proof of Stake (DPoS), Practical Byzantine Fault Tolerance (PBFT), Raft, Kafka, and Hotstuff, etc.
[0092] The following is a brief introduction to the application scenarios of the routing leakage determination method provided in this application.
[0093] Typically, ASs (Application Systems) have various business relationships. Depending on these relationships, ASs follow certain routing strategies, such as valley-free routing. However, because these business relationships involve internal decisions and economic benefits for AS administrators, they are rarely disclosed to external environments like the internet. This makes it difficult for ASs to verify the routing strategies of other networks, leading to undetected routing leaks and security vulnerabilities.
[0094] Based on this, this application provides a method for determining route leakage. This method can promptly determine whether route leakage has occurred in the network by utilizing routing information published by each AS on the blockchain without disclosing the business relationships between ASs. In this process, since the routing information of each AS is publicly disclosed through the blockchain, it possesses the characteristics of immutability and trustworthiness, ensuring the accuracy of the routing information and thus improving the accuracy rate of route leakage determination. Moreover, this routing information does not disclose the business relationships between ASs, thereby protecting the privacy of AS economic decisions and making it easily adopted by most ASs. When most ASs in the network deploy this solution, the accuracy rate of route leakage determination can be greatly improved.
[0095] Schematic illustration: The route leakage determination method provided in this application can be applied to scenarios requiring BGP routing, such as inter-domain communication, to promptly determine whether route leakage occurs in the network, thereby ensuring the security of network communication. For example, the scenarios to which this route leakage determination method can be applied include, but are not limited to: scenarios based on the Gao-Rexford criterion and valley-free forwarding policies, scenarios violating valley-free forwarding policies, and scenarios where differentiated forwarding policies are implemented for different routing prefixes, etc., which are not limited in this application. It should be noted that the specific application of this route leakage determination method in the above scenarios will be described in subsequent embodiments and will not be repeated here.
[0096] The implementation environment of the technical solution provided in this application is described below.
[0097] Figure 2 This is a schematic diagram illustrating the implementation environment of a route leakage determination method provided in an embodiment of this application. For example... Figure 2 As shown, the implementation environment includes AS node 101 and AS blockchain server 102. AS node 101 and AS blockchain server 102 are connected directly or indirectly via wired or wireless networks, without restriction. All network devices within the same AS are interconnected, run the same routing protocol, and are assigned the same ASN.
[0098] AS node 101 is used to send its routing information to the corresponding AS blockchain server 102, which then publishes the routing information to the blockchain. For any given AS node, the routing information includes: the AS node's identifier, at least one routing prefix, and neighboring nodes, etc. The routing prefix is the Internet Protocol (IP) prefix declared by the AS node (the specific form and content of the routing information will be described in subsequent embodiments and will not be repeated here). Illustratively, taking the first AS node as an example, this first AS node is used to publish its routing information to the blockchain; the routing information includes: the first AS node's identifier, at least one second routing prefix, and neighboring nodes, where the second routing prefix is the IP prefix declared by the first AS node. Furthermore, when receiving a BGP update message published by another AS node, AS node 101 is also used to determine whether the AS path is a path where routing leakage has occurred, based on the AS path in the BGP update message and the routing information of each AS node published on the blockchain. In some embodiments, the AS node 101 is a router, also known as a border gateway or border router, and this application embodiment does not limit this. It should be noted that in the route leakage determination method provided in this application embodiment, for any AS, the number of AS nodes 101 deployed in the AS can be more or less. The figure shown is only illustrative, and this application embodiment does not limit this.
[0099] AS blockchain server 102 is used to receive routing information sent by the corresponding AS node 101 and store the routing information on the blockchain in the form of blocks. Each AS deploys a corresponding AS blockchain server. In some embodiments, the transaction format corresponding to the routing information on the blockchain is called a route transit attestation transaction (RTAT), which is not limited in this application embodiment. In some embodiments, the AS blockchain server 102 runs in the form of a smart contract, periodically sending the consensus-reached routing information to the AS nodes of its AS. The AS blockchain server 102 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. The number of AS blockchain servers 102 can be more or less, which is not limited in this application embodiment.
[0100] In some embodiments, a database system is deployed on the AS blockchain server 102 to implement the function of publicizing routing information based on blockchain technology. (Illustratively, see reference to...) Figure 3 , Figure 3 This is a schematic diagram of the architecture of a database system provided in an embodiment of this application. For example... Figure 3 As shown, the database system comprises three parts: the application layer, the management layer, and the distributed ledger layer. The application layer provides functions such as BGP source address verification, BGP path tampering and route leakage detection, and digital certificates. The management layer synchronizes routing information among various AS nodes through processes such as transaction publishing and block consensus, and maintains metadata such as IP prefixes, AS numbers, and forwarding relationships for different ASs. The distributed ledger layer stores all data information on the blockchain and is also known as the data layer. It should be noted that... Figure 3 The architecture of the database system shown and the functions of each layer are only illustrative. In some embodiments, users can adjust the architecture of the database system according to their needs, and this application does not limit this.
[0101] In some embodiments, the aforementioned wireless or wired networks use standard communication technologies and / or protocols. The network is typically the Internet, but can be any network, including but not limited to local area networks (LANs), metropolitan area networks (MANs), wide area networks (WANs), mobile, wired or wireless networks, private networks, or any combination of virtual private networks. In some implementations, technologies and / or formats, including Hypertext Markup Language (HTML), Extensible Markup Language (XML), etc., are used to represent data exchanged over the network. Furthermore, conventional encryption technologies such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), Virtual Private Networks (VPNs), and Internet Protocol Security (IPsec) can be used to encrypt all or some links. In other embodiments, custom and / or dedicated data communication technologies can be used to replace or supplement the aforementioned data communication technologies.
[0102] The hardware structure of AS node 101 and AS blockchain server in the above implementation environment is described below.
[0103] This application provides a network device that can be configured as any AS node 101 in the above-described implementation environment.
[0104] Indicatively, Figure 4 This is a schematic diagram of the structure of a network device provided in an embodiment of this application. Figure 4 As shown, the network device 400 includes a memory 401, a processor 402, a communication interface 403, and a bus 404. The memory 401, processor 402, and communication interface 403 are interconnected via the bus 404.
[0105] Memory 401 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 401 may store at least one piece of program code. When the program code stored in memory 401 is executed by processor 402, processor 402 and communication interface 403 are used to execute the route leakage determination method performed by the AS node in the following method embodiment.
[0106] Processor 402 may be a network processor (NP), a central processing unit (CPU), an application-specific integrated circuit (ASIC), or an integrated circuit used to control the execution of the program in this application. Processor 402 may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The number of processors 402 may be one or more.
[0107] Communication interface 403 uses a transceiver module, such as a transceiver, to enable communication between network device 400 and other devices or communication networks. For example, data can be acquired through communication interface 403. Communication interface 403 can be an Ethernet interface, a Fast Ethernet (FE) interface, or a Gigabit Ethernet (GE) interface, etc.
[0108] The memory 401 and the processor 402 can be set separately or integrated together.
[0109] Bus 404 may include a path for transmitting information between various components of network device 400 (e.g., memory 401, processor 402, communication interface 403).
[0110] This application embodiment also provides a computing device that can be configured as the AS blockchain server 102 in the above-described implementation environment.
[0111] Indicatively, Figure 5 This is a schematic diagram of a computing device provided in an embodiment of this application. The computing device 500 can vary significantly due to different configurations or performance, including one or more processors 501 and one or more memories 502. The memory 502 stores at least one line of program code, which is loaded by the processor 501 and executed by the route leakage determination method performed by the AS blockchain server in the following method embodiment. Of course, the computing device 500 may also have wired or wireless network interfaces, a keyboard, and input / output interfaces for input and output. The computing device 500 also includes other components for implementing device functions, which will not be elaborated here.
[0112] It should be noted that in some embodiments, the AS blockchain server is deployed on a single computing device. In some embodiments, the AS blockchain server is deployed on multiple computing devices, and this application does not limit this.
[0113] The routing leakage determination method provided in the embodiments of this application will be described by way of example below.
[0114] Figure 6 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application. For example... Figure 6 As shown, schematically, this route leakage determination method is applicable to situations such as... Figure 2 In the implementation environment shown, the following are examples Figure 2 Taking any AS node shown as an example, the route leakage determination method provided in this application embodiment will be introduced. The method includes the following steps.
[0115] 601. The first AS node receives the BGP update message published by the second AS node.
[0116] In this embodiment, the first AS node belongs to the first AS, and the second AS node belongs to the second AS. The BGP update message is used to advertise routes. In some embodiments, the BGP update message includes the identifier of the second AS node (such as the ASN of the second AS), the IP prefix advertised by the second AS node, and the AS path, etc., which are not limited in this embodiment. The AS path indicates the multiple AS nodes traversed from the second AS node to the first AS node. In some embodiments, the BGP update message is also referred to as a BGP update packet.
[0117] 602. The first AS node obtains the AS path based on the BGP update message.
[0118] In this embodiment, the first AS node parses the BGP update message to obtain the AS path. For example, the BGP update message includes network layer reachability information (NLRI), i.e., a reachable route list, where the source address is the address of the second AS node S, the destination address is the address of the first AS node Q, and the addresses of AS nodes P and L appear sequentially in between. The first AS node then parses the BGP update message to obtain the AS path, which indicates that the multiple AS nodes traversed from the second AS node S to the first AS node Q are Q, L, P, and S.
[0119] 603. The first AS node obtains the routing information published to the blockchain by the multiple AS nodes in the AS path.
[0120] In this embodiment, the first AS node obtains routing information corresponding to the multiple AS nodes in the AS path based on their respective identifiers. This routing information includes the neighboring AS nodes of the corresponding AS node. Specifically, for any given AS node, its neighboring AS nodes refer to those nodes that conform to the routing and forwarding policy of that AS node. In other words, the neighboring AS nodes of that AS node are those neighboring nodes whose AS is permitted to receive and forward BGP update messages.
[0121] In some embodiments, the first AS node stores routing information published to the blockchain by each AS node in the network. The first AS node retrieves the routing information published to the blockchain by each AS node in the AS path, using the identifiers of the AS nodes as indexes. In some embodiments, the AS blockchain server corresponding to the first AS node periodically sends the routing information published to the blockchain by each AS node in the network to the first AS node in the form of a smart contract. In other embodiments, the AS blockchain service corresponding to the first AS node sends the routing information published to the blockchain by each AS node to the first AS node when the routing information published to the blockchain by each AS node changes; this embodiment does not limit this. By storing the routing information of each AS node on the first AS node, the first AS node can easily retrieve the corresponding routing information each time it receives a BGP update message, reducing message interaction and improving the efficiency of determining route leaks.
[0122] In some embodiments, the first AS node sends a routing information retrieval request to the AS blockchain server corresponding to the first AS node based on the identifiers of the various AS nodes in the AS path. Upon receiving the request, the AS blockchain server feeds back the corresponding routing information to the first AS node. This method of obtaining routing information in real time saves storage space for the first AS node and improves space utilization.
[0123] In some embodiments, an AS node and its corresponding neighboring AS nodes are referred to as a forwarding triple. For any given AS node, its routing information includes one or more forwarding triples; this embodiment does not limit this. In some embodiments, a forwarding triple consists of the identifiers of three AS nodes in an ordered manner, for example, the identifier being the AS's ASN; this embodiment does not limit this. Schematic, the forwarding triple of an AS node is represented as (a, b, c), where a and c indicate the ASN of the AS to which the BGP update message is to be sent and the ASN of the AS to which the AS node sending the BGP update message belongs, respectively, and b represents the ASN of the AS to which the AS node belongs. For example, taking any AS node B as an example, the routing information of AS node B includes two forwarding triples, represented as (C, B, A) and (D, B, E) respectively. The forwarding triple (C, B, A) indicates that AS node B can forward the BGP update message received from AS node A to AS node C; the forwarding triple (D, B, E) indicates that AS node B can forward the BGP update message received from AS node E to AS node D.
[0124] It should be noted that this routing information, including the forwarding triplet, has the following two advantages:
[0125] First, it is difficult to infer the business relationships between ASs from forwarding triples. AS business relationships are often related to the business decisions of the AS operating organization, making it difficult for related solutions to be adopted and deployed by various ASs. This form of routing information provides protection for their privacy. Specifically, for an AS, exposing its suppliers may provide targets for network attacks, and suppliers may also raise network access fees; exposing partners may allow competitors to analyze internal cooperation decisions; exposing customers may lead to other business competitors seizing important customers, affecting the organization's economic benefits. Therefore, the privacy of business relationships is important for network administrators. However, the forwarding relationship represented by forwarding triples is different; it itself is propagated along the AS path through BGP update messages, lacking strong privacy. Furthermore, it is difficult to infer the business relationships between ASs from forwarding triples. On the one hand, it is difficult for ASs observing forwarding triples to distinguish whether they are uplink or downlink paths, thus making it impossible to accurately identify the customer side; on the other hand, since suppliers and partners both have similar valley-free forwarding strategies, they are difficult to accurately distinguish from each other. In cases involving non-classical business relationships and special export forwarding strategies, it becomes even more difficult to infer business relationships from forwarding triples.
[0126] Secondly, forwarding triples can accurately express the routing forwarding policies between ASs. Route leakage detection is essentially related to the routing forwarding policies of AS nodes; business relationships are merely a general manifestation of these policies. Although inter-domain routing is a complex scenario, AS nodes almost never configure differentiated routing forwarding policies based on non-adjacent AS nodes. In other words, AS nodes only filter and forward messages based on their direct neighbors from which BGP update messages arrive. This phenomenon is called neighbor-based importing and exporting (NBIE). The aforementioned forwarding triples are based on NBIE. The nature of these forwarding triples is that they do not publicly disclose the business relationships between ASs and can accurately and unambiguously express the routing forwarding policies of each AS node. Since routing forwarding policies are the basis for determining whether route leakage has occurred...
[0127] Therefore, this method can improve the accuracy of route leakage determination while protecting the privacy of AS economic decision-making.
[0128] In some embodiments, the routing information also includes at least one target routing prefix corresponding to the AS node. That is, each AS node carries at least one target routing prefix in its routing information when publishing its own routing information to the blockchain. In some embodiments, BGP update messages from the same neighbor carrying different routing prefixes have different routing forwarding strategies. In other words, AS nodes can customize different routing forwarding strategies for different routing prefixes. For example, taking routing information including forwarding triples as an example, the BGP update message published by the second AS node includes two different routing prefixes p1 and p2. For any AS node L in the AS path, routing prefix p1 can be forwarded between AS node P and the first AS node Q, and can also be forwarded between AS node P and AS node C, while routing prefix p2 can only be forwarded between AS node P and AS node C. Based on this, when AS node L uploads routing information to the blockchain, the routing information includes: two forwarding triples (Q, L, P) and (C, L, P) corresponding to routing prefix p1; and one forwarding triple (C, L, P) corresponding to routing prefix p2.
[0129] Furthermore, when the aforementioned routing information also includes at least one target routing prefix corresponding to the AS node, the first AS node can obtain routing information matching the routing prefix carried in the BGP update message. Illustratively, the routing prefix carried in the BGP update message is referred to as the first routing prefix. The first AS node obtains at least one first routing prefix based on the BGP update message; this first routing prefix is the IP prefix advertised by the second AS node. Based on this at least one first routing prefix, it obtains routing information published on the blockchain by multiple AS nodes, where the at least one first routing prefix matches the at least one target routing prefix. In some embodiments, the first AS node uses the identifiers of multiple AS nodes in the AS path as indexes to locate the routing information published on the blockchain by each AS node, and uses the at least one first routing prefix as an index to obtain routing information matching the at least one first routing prefix from the routing information published on the blockchain by the multiple AS nodes. In other embodiments, the first AS node obtains the corresponding routing information by sending a routing information retrieval request to the corresponding AS blockchain server; this application embodiment does not limit this method.
[0130] It should be noted that by carrying at least one target route prefix in the routing information, the determination of AS-level route leakage can be refined to the route prefix level. When the first AS node detects whether the AS path is a path where route leakage has occurred, it can ensure that the path corresponding to the route prefix that conforms to the routing forwarding policy is guaranteed to have communication, thereby effectively improving the accuracy of route leakage determination.
[0131] Indicatively, for reference Figure 7 , Figure 7 This is a schematic diagram of routing information provided in an embodiment of this application. For example... Figure 7 As shown, this routing information includes: route prefix, AS node identifier (i.e., the ASN of the AS it belongs to), operator name, forwarding triple, transaction signature, etc. It should be understood that... Figure 7 The routing information shown is merely illustrative. In some embodiments, users can adjust the form or content of the routing information as needed. For example, the routing information may not include the routing prefix. Another example is setting the routing prefix to ALL (all) when there is no need to differentiate forwarding strategies for different routing prefixes. Yet another example is setting the last position in the forwarding triplet to empty when an AS node forwards its own advertised IP prefix, and so on. This application does not limit these embodiments.
[0132] 604. The first AS node detects the AS path based on the routing information published to the blockchain by the multiple AS nodes, and obtains routing detection information. The routing detection information indicates whether the AS path is a path where routing leakage has occurred.
[0133] In this embodiment, the first AS node detects the routing information of each AS node hop-by-hop based on the order of the multiple AS nodes indicated by the AS path, thus obtaining the routing detection information. Hop-by-hop detection of the routing information of each AS node means that the first AS node checks whether the neighboring nodes indicated by the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path. Since the routing information of the multiple AS nodes is published to the blockchain by the multiple AS nodes themselves, the routing information of the multiple AS nodes conforms to the inbound and outbound routing forwarding policies of the multiple AS nodes. By detecting whether the neighboring nodes indicated by the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path, it is possible to determine whether the inbound and outbound routing forwarding policies indicated by the AS path meet the requirements. This facilitates the first AS node in determining whether the current AS path is a path where routing leakage has occurred, improving the accuracy of routing leakage detection.
[0134] In some embodiments, during the hop-by-hop detection of routing information for each AS node, the first AS node generates a routing detection identifier for each AS node. Based on the routing detection identifier of each AS node, routing detection information is obtained, wherein the routing detection identifier indicates whether the corresponding AS node meets the routing forwarding conditions. The fact that the corresponding AS node meets the routing forwarding conditions indicates that, within the AS path, the forwarding of the BGP update message by the corresponding AS node conforms to the inbound and outbound routing forwarding policies of the corresponding AS node. Illustratively, this process includes the following steps 6041 and 6042.
[0135] 6041. The first AS node generates a route detection identifier for each AS node based on whether the neighboring nodes indicated by the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path.
[0136] Among these multiple AS nodes, the process by which the first AS node generates the route detection identifier for any AS node includes any of the following cases.
[0137] Scenario 1: If the neighboring node indicated by the routing information of any AS node is the same as the neighboring node of any AS node in the AS path, a first route detection identifier is generated for any AS node. The first route detection identifier indicates that any AS node meets the route forwarding condition.
[0138] Schematic, the AS path indicates that the multiple AS nodes traversed from the second AS node S to the first AS node Q are Q, L, P, and S. Taking any AS node L as an example, the first AS node Q checks the routing information of each AS node hop by hop. When it verifies the hop to AS node L, the routing information of AS node L indicates that the adjacent nodes are AS node Q and AS node P (for example, the routing information includes forwarding triples (Q, L, P) and (Q, L, M)), which are the same as the adjacent nodes of AS node L in this AS path. The first AS node generates a first route detection identifier. For example, the first route detection identifier is represented as Valid, but this embodiment of the application does not limit this.
[0139] Scenario 2: If the neighboring node indicated by the routing information of any AS node is different from the neighboring node of any AS node in the AS path, a second route detection identifier is generated for any AS node. The second route detection identifier indicates that any AS node does not meet the route forwarding conditions.
[0140] Schematic, the AS path indicates that the multiple AS nodes traversed from the second AS node S to the first AS node Q are Q, L, P, and S. Taking any AS node L as an example, the first AS node Q checks the routing information of each AS node hop by hop. When it verifies that the hop to AS node L is reached, the routing information of AS node L indicates that the adjacent nodes are AS node Q and AS node N (for example, the routing information includes forwarding triples (Q, L, P) and (Q, L, M)), which are different from the adjacent nodes of AS node L in this AS path. The first AS node generates a second route detection identifier. For example, the second route detection identifier is represented as Invalid, but this embodiment of the application does not limit this.
[0141] Scenario 3: If the routing information of any AS node is not obtained, a third route detection identifier for that AS node is generated, which indicates that the routing information of any AS node has not been obtained.
[0142] In some embodiments, when the first AS node performs step 603 above to obtain routing information of multiple AS nodes in the AS path, it may not obtain the routing information of a certain AS node. For example, the AS node may not have uploaded its own routing information to the blockchain, or the AS blockchain server corresponding to the first AS node may have experienced data loss when sending the routing information of each AS node, etc. This application embodiment does not limit this. In this case, the first AS node cannot determine whether the forwarding of the BGP update message by any AS node conforms to the inbound and outbound routing forwarding policy of any AS node, and generates a third route detection identifier. For example, the third route detection identifier is represented as Unknown, which is not limited in this application embodiment.
[0143] After step 6041, the first AS node generates a route detection identifier for each AS node through hop-by-hop detection. There are multiple types of route detection identifiers, which facilitates the subsequent targeted integration of the detection results of each hop in the AS path to obtain the route detection information of the AS path.
[0144] 6042. The first AS node obtains the route detection information based on the route detection identifier of each AS node.
[0145] In this process, the first AS node generates corresponding route detection information based on the type of the route detection identifier of each AS node. This process includes any of the following cases.
[0146] Scenario 1: If there is no first target AS node and no second target AS node among the multiple AS nodes, first route detection information is generated. The route detection identifier of the first target AS node is the second route detection identifier, and the route detection identifier of the second target AS node is the third route detection identifier. The first route detection information indicates that the AS path is a safe path.
[0147] In this embodiment, a route detection identifier of the first target AS node being a second route detection identifier indicates that the first target AS node does not meet the route forwarding conditions. A route detection identifier of the second target AS node being a third route detection identifier indicates that whether the second target AS node meets the route forwarding conditions is unknown. If neither of these two types of AS nodes exists among the plurality of AS nodes, it indicates that all of the plurality of AS nodes meet the route forwarding conditions, and the AS path has not experienced route leakage. The first AS node generates first route detection information. For example, this first route detection information may be represented as Secure, but this embodiment does not limit this representation.
[0148] Scenario 2: If the first target AS node exists among the multiple ASs, generate second route detection information, which indicates that the AS path is the path where route leakage has occurred.
[0149] In the case where a first target AS node exists among the multiple AS nodes, it indicates that an AS node in the AS path does not meet the routing forwarding conditions, and route leakage has occurred in the AS path. The first AS node then generates second route detection information. For example, this second route detection information may be represented as Insecure, but this embodiment of the application does not limit this.
[0150] In some embodiments, the first AS node discards the BGP update message in this situation. This process can also be understood as filtering the AS path to prevent subsequent traffic from flooding into the AS node where route leakage has occurred, thereby improving the security of inter-AS communication.
[0151] Scenario 3: If there is a second target AS node among the multiple ASs, and there is no first target AS node, generate third route detection information. This third route detection information indicates that the AS path is a path with unknown security.
[0152] In the case where a second target AS node exists among the multiple AS nodes but no first target AS node exists, it indicates that in addition to the AS nodes that meet the routing forwarding conditions, there is an AS node whose compliance with the routing forwarding conditions is unknown. The first AS node cannot determine whether a route leak has occurred in this AS path, and the security of this AS path is unknown. Therefore, the first AS node generates third route detection information. For example, this third route detection information is represented as Normal, but this embodiment of the application does not limit this.
[0153] In some embodiments, the first AS node identifies the AS path as a candidate path and adds it to its routing table. This process can also be understood as reducing the priority of the AS path, prioritizing the selection of safe AS paths in subsequent traffic transmission, thereby maximizing the reasonable balance between network reachability and security.
[0154] After steps 6041 and 6042, the first AS node determines whether the AS path is a path where route leakage has occurred by hop-by-hop detection. In this process, it is determined whether each AS node meets the routing forwarding conditions, thereby integrating the situation of the entire AS path to obtain route leakage detection information, which effectively improves the accuracy of route leakage determination.
[0155] Furthermore, when the routing information also includes at least one target routing prefix corresponding to the AS node, the process by which the first AS node detects the AS path and obtains routing detection information is similar to steps 6041 and 6042 described above. Specifically, the first AS node detects the AS path based on each first routing prefix carried in the BGP update message and the routing information published to the blockchain by the multiple AS nodes, thus obtaining routing detection information. In this way, the determination of AS-level route leakage is refined to the routing prefix level. This ensures that paths corresponding to routing prefixes that conform to the routing forwarding policy are guaranteed to have communication, and also allows for the selective discarding (or filtering) of AS paths that have experienced route leakage, thereby greatly improving the accuracy of route leakage determination.
[0156] For example, taking routing information including forwarding triples as an example, the BGP update message includes two different routing prefixes p1 and p2, and the AS path indicates that the multiple AS nodes are Q, L, P, and S. For any AS node L in the AS path, the routing information of AS node L includes: two forwarding triples (Q, L, P) and (C, L, P) corresponding to routing prefix p1; and one forwarding triple (C, L, P) corresponding to routing prefix p2. During hop-by-hop detection, when the first AS node detects the hop of AS node L, for the AS path corresponding to routing prefix p1, the routing information of AS node L indicates that the adjacent nodes are AS nodes Q and P, which are the same as the adjacent nodes of AS node L in this AS path, and the first AS node generates a first routing detection identifier; for the AS path corresponding to routing prefix p2, the routing information of AS node L indicates that the adjacent nodes are AS nodes C and P, which are different from the adjacent nodes of AS node L in this AS path, and the first AS node generates a second routing detection identifier. Based on this, when all other AS nodes correspond to the first route detection identifier, the first AS node generates first route detection information for the AS path corresponding to route prefix p1, generates second route detection information for the AS path corresponding to route prefix p2, and discards the AS path.
[0157] It should be noted that in steps 603 and 604 above, the first AS node, after obtaining the routing information published to the blockchain by the multiple AS nodes in the AS path, checks the routing information of each AS node hop-by-hop based on the routing information published to the blockchain by the multiple AS nodes, thereby determining whether the AS path is a path where routing leakage has occurred. In some embodiments, the first AS node obtains the routing information published to the blockchain by each AS node hop-by-hop based on the order of the multiple AS nodes indicated by the AS path, and checks the routing information of each AS node when it obtains the routing information of the AS node. That is, the embodiments of this application do not limit the timing of the first AS node obtaining the routing information of multiple AS nodes.
[0158] In summary, in the route leakage determination method provided in this application embodiment, when the first AS node receives a BGP update message published by the second AS node, it obtains the AS path in the BGP update message, and then uses the routing information published to the blockchain by multiple AS nodes along the AS path to detect the AS path and promptly determine whether a route leakage has occurred. In this process, the routing information of multiple AS nodes is publicly disclosed through the blockchain, possessing the characteristics of immutability and trustworthiness, thus ensuring the accuracy of the routing information and improving the accuracy of route leakage determination. Moreover, this routing information does not disclose the business relationships between ASes, thus protecting the privacy of AS economic decisions and making it easily adopted by most ASes. When most ASes in the network determine route leakage based on the above method, the accuracy of route leakage determination can be greatly improved. Furthermore, this method supports gradual deployment, self-deployment, and self-benefit; even in scenarios where only some AS nodes in the network deploy the above scheme, it can still provide a certain degree of route leakage detection capability.
[0159] Through the above Figure 6 The embodiments shown illustrate the implementation process of the route leakage determination method provided in this application. The implementation process of the route leakage determination method will be illustrated below based on different application scenarios.
[0160] Based on the above description of the applicable scenarios of the embodiments of this application, it can be seen that the route leakage determination method can be applied to scenarios including but not limited to: scenarios based on the Gao-Rexford criterion and valley-free forwarding policy, scenarios that violate the valley-free forwarding policy, and scenarios that differentiate and customize forwarding policies for different route prefixes, etc.
[0161] Indicatively, for reference Figure 8 , Figure 8 This is a schematic diagram illustrating an application scenario of a route leakage determination method provided in an embodiment of this application. For example... Figure 8As shown, this route leakage determination method can be applied to scenarios based on the Gao-Rexford criterion and valley-free forwarding policy, as well as scenarios that violate the valley-free forwarding policy. Specifically, the BGP update message published by vendor AS node 2 can be forwarded to customer AS node 5 through AS node 1. This routing forwarding policy follows the Gao-Rexford criterion and valley-free forwarding policy. Accordingly, the forwarding triplet generated by AS node 1 for this routing forwarding policy is (5, 1, 2). The BGP update message published by vendor AS node 2 can also be forwarded to vendor AS node 3 through AS node 1. This routing forwarding policy violates the valley-free forwarding policy. Accordingly, the forwarding triplet generated by AS node 1 for this routing forwarding policy is (3, 1, 2). Furthermore, the BGP update message published by AS node 4 can be forwarded to vendor AS node 3 through AS node 1. This routing forwarding policy is a forwarding policy with a special business relationship. Accordingly, the forwarding triplet generated by AS node 1 for this routing forwarding policy is (3, 1, 4). In this complex scenario, when any AS node in the network detects AS node 1 during the process of determining route leakage, it can promptly determine whether a route leakage has occurred based on the routing information published by AS node 1, and the accuracy of route leakage determination is high.
[0162] Indicatively, for reference Figure 9 , Figure 9 This is a schematic diagram illustrating an application scenario of another route leakage determination method provided in this application embodiment. For example... Figure 9 As shown, this route leakage determination method can be applied to scenarios where different routing prefixes are used to customize forwarding strategies. Specifically, in this scenario, the routing information includes not only the forwarding triplet but also at least one target routing prefix. In the BGP update message published by AS Node 2, the path corresponding to routing prefix p1 can be forwarded to AS Node 3 via AS Node 1, and the path corresponding to routing prefix p2 can be forwarded to AS Node 4 via AS Node 1. In this scenario, by including at least one target routing prefix in the routing information, the route leakage determination at the AS node level is refined to the routing prefix level. This ensures that paths corresponding to routing prefixes that conform to the routing forwarding strategy are guaranteed to have communication, and also allows for the selective discarding (or filtering) of AS node paths that have experienced route leakage, thereby significantly improving the accuracy of route leakage determination.
[0163] The above Figure 8 and Figure 9 Based on the scenarios in which the embodiments of this application can be applied, the method for determining route leakage is illustrated with examples below. Figures 10 to 12 Using three specific application scenarios as examples, this paper illustrates the protective effect of the routing leakage determination method on network communication security.
[0164] Scenario 1: Based on the Gao-Rexford criterion and valley-free forwarding strategy.
[0165] Indicatively, for reference Figure 10 , Figure 10 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application. Figure 10 Figure (a) illustrates the scenario without this solution deployed. AS node L, due to misconfiguration, violates the valley-free forwarding policy, forwarding BGP update messages from vendor AS node P to another vendor AS node Q, resulting in route leakage. When a large number of remote AS nodes need to access the source AS node, a traffic diversion occurs at vendor AS node Q, causing traffic that should have been directly forwarded to AS node P via peer links to flood into the leaked AS node L. The potential consequences are as follows: 1) AS node L, unable to handle the large volume of traffic, experiences network congestion and refuses to provide services, becoming completely unreachable. 2) Traffic from affected AS nodes is dropped at AS node L, preventing them from accessing the source AS. 3) Service interruption occurs from the source AS node to the affected AS nodes, impacting business continuity and availability. 4) Other traffic passing through AS node L is dropped due to AS node L's failure, causing AS node L's customers to disconnect from the network. 5) When AS node L has strong processing capabilities, it may eavesdrop on or tamper with the data of the affected AS node, thus causing a BGP hijacking event.
[0166] like Figure 10As shown in Figure (b), this figure illustrates the scenario where this solution has been deployed. AS node L has adopted and deployed this solution, and its corresponding AS blockchain server becomes a member node in the blockchain system. In the early stages of network establishment, AS node L publishes corresponding routing information based on its own routing forwarding policy. This routing information includes forwarding triples of (Q, L, M) and (N, L, P). When AS node L misconfigures its routing forwarding policy, violating the valleyless forwarding policy, the AS blockchain server corresponding to AS node L will not update the corresponding routing information because this behavior has not been approved by the management organization. When a leaked BGP update message is transmitted to AS node Q, if AS node Q has also deployed this solution, AS node Q can detect the AS path in the BGP update message based on the routing information of each AS node in the network stored within it. This AS path indicates that the multiple AS nodes traversed from the source AS node S to AS node Q are Q, L, P, and S. When AS node L is detected, its routing information contains forwarding triples (Q, L, M) and (N, L, P), which are different from its neighboring nodes in the AS path. Therefore, this hop is marked as Invalid, making the entire AS path insecure. AS node Q can filter this insecure path and choose the Secure / Normal route from its companion AS node P. Ultimately, traffic will be transmitted along the direction indicated by the solid line in the diagram, and route leakage will not occur.
[0167] Scenario 2: Scenarios that violate the Wugu forwarding strategy.
[0168] Indicatively, for reference Figure 11 , Figure 11 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application. Figure 11 As shown, an atypical inter-domain business relationship is established between AS node R and AS node L: BGP update messages from AS node R to AS node L cannot be forwarded to AS node L's supplier AS node Q, but can be forwarded to another supplier AS node P of AS node L. In this case, the relationship between AS node R and AS node L does not meet either the supplier / partner condition or the customer condition. In other words, this forwarding relationship does not comply with the valley-free forwarding policy. Furthermore, supplier AS node P and AS node Q can forward messages to each other through AS node L, which, although complying with the Gao-Rexford criterion, also violates the valley-free forwarding policy.
[0169] In this scenario, AS node L configures corresponding routing and forwarding policies based on its complex business relationships and uploads the routing information to the blockchain. Illustratively, this routing information includes forwarding triples (P, L, R), (P, L, Q), and (Q, L, P). If AS node L experiences a route leak and forwards a BGP update message from AS node R to AS node Q, AS node Q can filter out BGP update messages containing the forwarding triple (Q, L, R) based on the routing information of each AS node in its stored network. This ensures that traffic will not be transmitted along the direction indicated by the dashed line in the diagram, but will instead reach the source AS node smoothly along the direction indicated by the solid line.
[0170] Scenario 3: A scenario where different routing prefixes are used to customize forwarding strategies.
[0171] Indicatively, for reference Figure 12 , Figure 12 This is a schematic diagram of a route leakage determination method provided in an embodiment of this application. Figure 12 As shown, the BGP update message sent by the source AS node includes two different route prefixes, p1 and p2. Route prefix p1 can be forwarded between AS nodes P and Q via AS node L, while route prefix p2 cannot; it can only be forwarded directly through the peer links of AS nodes P and Q and cannot pass through AS node L.
[0172] In this scenario, AS node L configures the corresponding routing and forwarding policy and uploads the routing information to the blockchain. Illustratively, this routing information includes four forwarding triples corresponding to both routing prefixes p1 and p2: (C, L, P), (P, L, C), (Q, L, C), and (C, L, Q), set to ALL. Additionally, routing prefix p1 also corresponds to one forwarding triple (Q, L, P). Therefore, under normal circumstances, when a remote AS node accesses the source AS node based on routing prefix p1, it will follow path 1 in the diagram; when it accesses the source AS node based on routing prefix p2, it will follow path 2 in the diagram.
[0173] If AS node L experiences route leakage—that is, AS node L forwards BGP update messages containing route prefix p2 to vendor AS node Q—traffic will be forwarded to AS node L if AS node Q has not deployed this solution, causing congestion or even crashing of AS node L, affecting AS node L, the source AS node, and a large number of remote AS nodes. If AS node Q has deployed this solution, it can filter AS paths corresponding to route prefix p2 based on the routing information of each AS node in its stored network. Thus, when a large number of remote AS nodes access the source AS node based on route prefix p1, AS node Q will choose to forward the message to AS node L; and when accessing the source AS node based on route prefix p1, it will choose to forward the message to AS node P.
[0174] In summary, the route leakage determination method provided in this application can be applied to various scenarios and provides accurate route leakage detection. During this process, the routing information of multiple AS nodes is publicly disclosed through a blockchain, possessing the characteristics of immutability and trustworthiness, thus ensuring the accuracy of the routing information and improving the accuracy of route leakage determination. Moreover, this routing information does not publicly disclose the business relationships between ASes, thereby protecting the privacy of AS economic decisions and making it easily adopted by most ASes. When most ASes in the network determine route leakage based on the above method, the accuracy of route leakage determination can be greatly improved. Furthermore, this method supports progressive deployment, self-deployment, and self-benefit; even in scenarios where only some AS nodes in the network deploy the above scheme, it can still provide a certain degree of route leakage detection capability.
[0175] Figure 13 This is a schematic diagram of a route leakage determination device provided in an embodiment of this application. Figure 13 As shown, the route leakage determination device 1300 is used to perform the steps executed by the first AS node in the route leakage determination method described above. Schematic, the route leakage determination device 1300 includes, but is not limited to: a receiving module 1301, a first acquisition module 1302, a second acquisition module 1303, and a detection module 1304.
[0176] The receiving module 1301 is used to receive Border Gateway Protocol (BGP) update messages published by the second AS node;
[0177] The first acquisition module 1302 is used to acquire the AS path based on the BGP update message. The AS path indicates multiple AS nodes traversed from the second AS node to the first AS node.
[0178] The second acquisition module 1303 is used to acquire the routing information published to the blockchain by the multiple AS nodes in the AS path, and the routing information includes the adjacent AS nodes of the corresponding AS node.
[0179] The detection module 1304 is used to detect the AS path based on the routing information published to the blockchain by the multiple AS nodes, and obtain routing detection information, which indicates whether the AS path is a path where routing leakage has occurred.
[0180] In some embodiments, the routing information further includes at least one target routing prefix of the corresponding AS node, and the second acquisition module 1303 is used to:
[0181] Based on the BGP update message, at least one first routing prefix is obtained, which is the Internet Protocol IP prefix announced by the second AS node;
[0182] Based on the at least one first routing prefix, obtain the routing information published on the blockchain by the multiple AS nodes, wherein the at least one first routing prefix matches the at least one target routing prefix.
[0183] In some embodiments, the detection module 1304 is configured to:
[0184] Based on the order of the multiple AS nodes indicated by the AS path, the routing information of each AS node is detected hop-by-hop to obtain the routing detection information.
[0185] In some embodiments, the detection module 1304 is configured to:
[0186] Based on whether the neighboring nodes indicated by the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path, a route detection identifier is generated for each AS node. The route detection identifier indicates whether the corresponding AS node meets the route forwarding conditions.
[0187] The route detection information is obtained based on the route detection identifier of each AS node.
[0188] In some embodiments, the detection module 1304 is configured to:
[0189] For any AS node among the plurality of AS nodes, if the neighboring node indicated by the routing information of any AS node is the same as the neighboring node of any AS node in the AS path, a first route detection identifier is generated for any AS node, and the first route detection identifier indicates that any AS node meets the route forwarding condition.
[0190] If the neighboring node indicated by the routing information of any AS node is different from the neighboring node of any AS node in the AS path, a second route detection identifier is generated for any AS node, and the second route detection identifier indicates that any AS node does not meet the route forwarding condition.
[0191] If routing information for any AS node is not obtained, a third routing detection identifier for that AS node is generated, indicating that routing information for that AS node has not been obtained.
[0192] In some embodiments, the detection module 1304 is configured to:
[0193] If neither the first target AS node nor the second target AS node exists among the multiple AS nodes, first route detection information is generated. The route detection identifier of the first target AS node is the second route detection identifier, and the route detection identifier of the second target AS node is the third route detection identifier. The first route detection information indicates that the AS path is a safe path.
[0194] If the first target AS node exists among the multiple ASs, generate second route detection information, which indicates that the AS path is the path where route leakage has occurred.
[0195] If the second target AS node exists among the multiple ASs, but the first target AS node does not exist, third route detection information is generated, which indicates that the AS path is a path with unknown security.
[0196] In some embodiments, the device further includes:
[0197] The discard module is used to discard the BGP update message if the route detection information indicates that the AS path is a path where a route leak has occurred.
[0198] In some embodiments, the device further includes:
[0199] Add a module to identify the AS path as an alternative path and add it to the routing table of the first AS node if the route detection information indicates that the AS path is a path with unknown security.
[0200] In some embodiments, the device further includes:
[0201] The publishing module is used to publish the routing information of the first AS node to the blockchain;
[0202] The routing information of the first AS node includes: the identifier of the first AS node, at least one second routing prefix of the first AS node, and the neighboring nodes of the first AS node, wherein the second routing prefix is the IP prefix advertised by the first AS node.
[0203] It should be noted that the route leakage determination model provided in the above embodiments is only an example of the division of the above functional modules when determining route leakage. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the route leakage determination device provided in the above embodiments and the above method embodiments belong to the same concept, and its specific implementation process can be found in the method embodiments, which will not be repeated here.
[0204] In this application, the terms "first," "second," etc., are used to distinguish identical or similar items that have substantially the same function and purpose. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor does it limit the quantity or order of execution. It should also be understood that although the following description uses the terms "first," "second," etc., to describe various elements, these elements should not be limited by the terms. These terms are merely used to distinguish one element from another. For example, without departing from the various examples described, a first AS can be referred to as a second AS, and similarly, a second AS can be referred to as a first AS. Both a first AS and a second AS can be AS, and in some cases, they can be separate and distinct ASs.
[0205] In this application, the term "at least one" means one or more, and the term "multiple" means two or more. For example, multiple AS means two or more AS.
[0206] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0207] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a program product. This program product includes one or more program instructions. When these program instructions are loaded and executed on a computing device, the processes or functions according to the embodiments of this application are generated, in whole or in part.
[0208] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0209] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A method for determining route leakage, characterized in that, The method, executed by the first autonomous system (AS) node, includes: Receive Border Gateway Protocol (BGP) update messages published by the second AS node; Based on the BGP update message, obtain the AS path, which indicates the multiple AS nodes traversed from the second AS node to the first AS node; Obtain the routing information published to the blockchain by the multiple AS nodes in the AS path. The routing information includes one or more forwarding triples corresponding to the AS node. The forwarding triple includes the corresponding AS node and two adjacent AS nodes of the corresponding AS node. The forwarding triple is represented as (a, b, c), where a is the identifier of the AS node to which the BGP update message is to be sent, b is the identifier of the corresponding AS node, and c is the identifier of the AS node that sends the BGP update message. The AS node to which the BGP update message is to be sent and the AS node that sends the BGP update message are both the adjacent AS nodes. For each of the plurality of AS nodes, a route detection identifier is generated based on whether the neighboring nodes included in each forwarding triplet in the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path. The route detection identifier indicates whether the corresponding AS node meets the route forwarding conditions. Based on the route detection identifier of each AS node, route detection information is obtained, which indicates whether the AS path is a path where route leakage has occurred.
2. The method according to claim 1, characterized in that, The routing information also includes at least one target route prefix for the corresponding AS node, and obtaining the routing information published to the blockchain by the plurality of AS nodes in the AS path includes: Based on the BGP update message, at least one first routing prefix is obtained, where the first routing prefix is the Internet Protocol IP prefix announced by the second AS node; Based on the at least one first routing prefix, obtain the routing information published on the blockchain by the plurality of AS nodes, wherein the at least one first routing prefix matches the at least one target routing prefix.
3. The method according to claim 1, characterized in that, For each of the plurality of AS nodes, a route detection identifier is generated based on whether the neighboring nodes included in each forwarding triplet in the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path, including: For any AS node among the plurality of AS nodes, if the neighboring node indicated by the routing information of any AS node is the same as the neighboring node of any AS node in the AS path, a first route detection identifier is generated for any AS node, and the first route detection identifier indicates that any AS node meets the route forwarding condition. If the neighboring node indicated by the routing information of any AS node is different from the neighboring node of any AS node in the AS path, a second route detection identifier is generated for any AS node, and the second route detection identifier indicates that any AS node does not meet the route forwarding conditions. If routing information for any AS node is not obtained, a third routing detection identifier for that AS node is generated, indicating that routing information for any AS node has not been obtained.
4. The method according to claim 3, characterized in that, The route detection information obtained based on the route detection identifier of each AS node includes: If neither the first target AS node nor the second target AS node exists among the plurality of AS nodes, first route detection information is generated, wherein the route detection identifier of the first target AS node is the second route detection identifier, and the route detection identifier of the second target AS node is the third route detection identifier, and the first route detection information indicates that the AS path is a safe path; If the first target AS node exists among the plurality of ASs, second route detection information is generated, and the second route detection information indicates that the AS path is a path where route leakage has occurred; If the second target AS node exists among the plurality of ASs, and the first target AS node does not exist, third route detection information is generated, and the third route detection information indicates that the AS path is a path with unknown security.
5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: If the route detection information indicates that the AS path is a path where a route leak has occurred, discard the BGP update message.
6. The method according to any one of claims 1 to 4, characterized in that, The method further includes: If the routing detection information indicates that the AS path is a path with unknown security, the AS path is identified as a candidate path and added to the routing table of the first AS node.
7. The method according to any one of claims 1 to 4, characterized in that, The method further includes: The routing information of the first AS node is published to the blockchain; The routing information of the first AS node includes: the identifier of the first AS node, at least one second routing prefix of the first AS node, and the neighboring nodes of the first AS node, wherein the second routing prefix is the IP prefix advertised by the first AS node.
8. A route leakage determination device, characterized in that, The device includes: The receiving module is used to receive Border Gateway Protocol (BGP) update messages published by the second AS node. The first acquisition module is used to acquire an AS path based on the BGP update message, wherein the AS path indicates multiple AS nodes traversed from the second AS node to the first AS node. The second acquisition module is used to acquire routing information published to the blockchain by the multiple AS nodes in the AS path. The routing information includes one or more forwarding triples corresponding to the AS node. The forwarding triple includes the corresponding AS node and two adjacent AS nodes of the corresponding AS node. The forwarding triple is represented as (a, b, c), where a is the identifier of the AS node to which the BGP update message is about to be sent, b is the identifier of the corresponding AS node, and c is the identifier of the AS node that sends the BGP update message. The AS node to which the BGP update message is about to be sent and the AS node that sends the BGP update message are both the adjacent AS nodes. The detection module is used for: For each of the plurality of AS nodes, a route detection identifier is generated based on whether the neighboring nodes included in each forwarding triplet in the routing information of each AS node are the same as the neighboring nodes of each AS node in the AS path. The route detection identifier indicates whether the corresponding AS node meets the route forwarding conditions. Based on the route detection identifier of each AS node, route detection information is obtained, which indicates whether the AS path is a path where route leakage has occurred.
9. The apparatus according to claim 8, characterized in that, The routing information also includes at least one target route prefix for the corresponding AS node, and the second acquisition module is used for: Based on the BGP update message, at least one first routing prefix is obtained, where the first routing prefix is the Internet Protocol IP prefix announced by the second AS node; Based on the at least one first routing prefix, obtain the routing information published on the blockchain by the plurality of AS nodes, wherein the at least one first routing prefix matches the at least one target routing prefix.
10. The apparatus according to claim 8, characterized in that, The detection module is used for: For any AS node among the plurality of AS nodes, if the neighboring node indicated by the routing information of any AS node is the same as the neighboring node of any AS node in the AS path, a first route detection identifier is generated for any AS node, and the first route detection identifier indicates that any AS node meets the route forwarding condition. If the neighboring node indicated by the routing information of any AS node is different from the neighboring node of any AS node in the AS path, a second route detection identifier is generated for any AS node, and the second route detection identifier indicates that any AS node does not meet the route forwarding conditions. If routing information for any AS node is not obtained, a third routing detection identifier for that AS node is generated, indicating that routing information for any AS node has not been obtained.
11. The apparatus according to claim 10, characterized in that, The detection module is used for: If neither the first target AS node nor the second target AS node exists among the plurality of AS nodes, first route detection information is generated, wherein the route detection identifier of the first target AS node is the second route detection identifier, and the route detection identifier of the second target AS node is the third route detection identifier, and the first route detection information indicates that the AS path is a safe path; If the first target AS node exists among the plurality of ASs, second route detection information is generated, and the second route detection information indicates that the AS path is a path where route leakage has occurred; If the second target AS node exists among the plurality of ASs, and the first target AS node does not exist, third route detection information is generated, and the third route detection information indicates that the AS path is a path with unknown security.
12. The apparatus according to any one of claims 8 to 11, characterized in that, The device further includes: The discard module is used to discard the BGP update message if the route detection information indicates that the AS path is a path where route leakage has occurred.
13. The apparatus according to any one of claims 8 to 11, characterized in that, The device further includes: An addition module is used to determine the AS path as a candidate path and add it to the routing table of the first AS node if the routing detection information indicates that the AS path is a path with unknown security.
14. The apparatus according to any one of claims 8 to 11, characterized in that, The device further includes: The publishing module is used to publish the routing information of the first AS node to the blockchain; The routing information of the first AS node includes: the identifier of the first AS node, at least one second routing prefix of the first AS node, and the neighboring nodes of the first AS node, wherein the second routing prefix is the IP prefix advertised by the first AS node.
15. A network device, characterized in that, The network device includes a processor and a memory, the memory being used to store at least one piece of program code, which is loaded by the processor and executed as the routing leakage determination method as described in any one of claims 1 to 7.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store at least one piece of program code, the at least one piece of program code being used to perform the route leakage determination method as described in any one of claims 1 to 7.
17. A computer program product, characterized in that, The computer program product includes one or more program instructions that, when loaded and run on a network device, cause the network device to perform the route leakage determination method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Secure route identification method and device
CN111385246A