Routing data anomaly detection method and related equipment based on RPKI

By performing resource public key infrastructure technology analysis and periodic detection on real-time gateway data, the problem of existing technologies being unable to quickly and accurately determine routing origin authorization anomalies in real time is solved, achieving more accurate detection and reliable repair, and improving network security.

CN119788339BActive Publication Date: 2025-09-23PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411837319.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-09-23
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

In the existing technology, routing origin authorization anomaly detection cannot quickly and in real time determine the actual authorization status of gateway data during RPKI use, resulting in the inability to perform corresponding repairs in a timely manner.

Method used

By performing resource public key infrastructure technology analysis on real-time gateway data, we can determine whether it supports RPKI, conduct gateway prefix hijacking detection and route origin authorization anomaly detection, repeat the detection after a preset period, and use assertion replacement data to repair abnormal data.

Benefits of technology

The accuracy of route origin authorization detection and the reliability of abnormal data repair are improved, ensuring network security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788339B_ABST
    Figure CN119788339B_ABST
Patent Text Reader

Abstract

The embodiments of the present application propose a method and related equipment for detecting anomalies in routing data based on RPKI, and the method includes: first, obtaining routing origin data from real-time gateway data; then, performing resource public key infrastructure technical analysis on the routing origin data to obtain a resource public key infrastructure technical analysis result; then, performing gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result, or performing routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result, and performing routing origin authorization anomaly detection on the routing origin data again after a preset detection period; finally, obtaining assertion replacement data corresponding to the routing origin data, and repairing the routing origin data based on the assertion replacement data, thereby improving the accuracy of routing origin authorization anomaly detection on the gateway data, and further improving the accuracy and reliability of repairing the abnormal gateway data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a routing data anomaly detection method and related equipment based on RPKI. Background Art

[0002] Routing origin authorization anomaly detection is a key method for ensuring data security within a network framework that supports resource public key infrastructure (RPKI). It is often combined with gateway data anomaly detection. During network communications, data flows through the gateway are monitored and analyzed to identify and flag data points or events that support RPKI and do not conform to normal behavior patterns. This process is crucial for maintaining network instability and stability by helping to promptly identify potential security threats, system failures, or other abnormal behavior.

[0003] In related technologies, routing origin authorization anomaly detection for gateway data typically involves pre-emptive anomaly allocation detection of resource-related data in the public key infrastructure (RPKI). The anomaly detection status is then analyzed based on the results. However, due to the diverse nature of routing origin authorization anomaly detection, pre-emptive anomaly detection alone cannot quickly and accurately determine the actual routing origin authorization status of gateway data during RPKI use, and thus cannot perform corresponding remediation. Summary of the Invention

[0004] The embodiments of the present application provide a method and related equipment for detecting anomalies in routing data based on RPKI, which can improve the accuracy of routing origin authorization detection of gateway data and improve the reliability of repairing abnormal gateway data.

[0005] To achieve the above objectives, a first aspect of an embodiment of the present application proposes a method for detecting anomalies in routing data based on RPKI, the method comprising:

[0006] Obtain route origin data from real-time gateway data;

[0007] Performing resource public key infrastructure technical analysis on the routing origin data to obtain a resource public key infrastructure technical analysis result;

[0008] When the resource public key infrastructure technology analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology, performing a gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result;

[0009] When the resource public key infrastructure technology analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, performing a routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result, and performing the routing origin authorization anomaly detection on the routing origin data again after a preset detection period;

[0010] Based on the gateway prefix anomaly detection result or the routing anomaly detection result, assertion replacement data corresponding to the routing origin data is acquired, and the routing origin data is repaired based on the assertion replacement data.

[0011] In some embodiments, performing resource public key infrastructure technical parsing on the routing origin data to obtain a resource public key infrastructure technical parsing result includes:

[0012] Obtaining a target code number identifier corresponding to the routing origin data;

[0013] The target code number identifier is matched with a plurality of code number identifiers in a resource public key infrastructure database, and the resource public key infrastructure technical analysis result is obtained based on the matching result, wherein the code number identifier is associated with routing origin authorization data.

[0014] In some embodiments, performing gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result includes:

[0015] Obtaining routing origin data from the real-time gateway data;

[0016] The routing origin data is matched with the authoritative data in the Internet resource database to obtain the gateway prefix anomaly detection result.

[0017] In some embodiments, performing routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result includes:

[0018] Obtaining routing origin authorization data of the real-time gateway data and the number of routing origin authorization data corresponding to the routing origin authorization data;

[0019] When there are multiple routing origin authorization data, performing attribution association detection on the multiple routing origin authorization data to obtain the routing anomaly detection result;

[0020] When the number of the routing origin authorization data is one, a routing origin authorization change detection is performed on the routing origin authorization data to obtain the routing anomaly detection result.

[0021] In some embodiments, performing attribution association detection on the plurality of routing origin authorization data to obtain the routing anomaly detection result includes:

[0022] Obtaining the authorization agency of each routing origin authorization data, and obtaining the agency association chain of each authorization agency;

[0023] When all the authorization agencies belong to the same agency association chain, performing routing origin authorization change detection on a plurality of routing origin authorization data to obtain the routing anomaly detection result;

[0024] When there are at least two authorized institutions that do not belong to the same institution association chain, a routing anomaly detection result is generated to indicate that an anomaly exists in the routing origin data.

[0025] In some embodiments, after performing the routing origin authorization anomaly detection again on the routing origin data after a preset detection period, the method further includes:

[0026] When the routing origin authorization data corresponding to the routing origin data cannot be detected, matching multiple code number identifiers from the routing certificate revocation list based on the target code number identifier to obtain a revocation matching result;

[0027] Based on the revocation matching result, a routing anomaly detection result is generated for characterizing that the routing origin authorization data is anomaly.

[0028] In some embodiments, the acquiring, based on the gateway prefix anomaly detection result or the routing anomaly detection result, assertion replacement data corresponding to the routing origin data, and repairing the routing origin data based on the assertion replacement data, includes:

[0029] When the gateway prefix anomaly detection result or the route anomaly detection result indicates that the route origin data is abnormal, prefix data filtering is performed on the real-time gateway data to obtain filtered code number data;

[0030] Obtaining the assertion replacement data corresponding to the filtering code number data from an authoritative database;

[0031] The resource public key data information corresponding to the real-time gateway data in the resource public key infrastructure database is replaced based on the assertion replacement data.

[0032] To achieve the above-mentioned purpose, a second aspect of an embodiment of the present application provides a routing data anomaly detection device based on RPKI, the device comprising:

[0033] The code number data acquisition module is used to obtain the routing origin data from the real-time gateway data;

[0034] A resource technology analysis module, configured to perform resource public key infrastructure technology analysis on the routing origin data to obtain a resource public key infrastructure technology analysis result;

[0035] A gateway anomaly detection module is configured to perform a gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result when the resource public key infrastructure technology analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology;

[0036] a routing detection module configured to, when the resource public key infrastructure technology analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, perform routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result, and perform the routing origin authorization anomaly detection on the routing origin data again after a preset detection period;

[0037] A repair module is used to obtain assertion replacement data corresponding to the routing origin data based on the gateway prefix anomaly detection result or the routing anomaly detection result, and repair the routing origin data based on the assertion replacement data.

[0038] To achieve the above-mentioned objectives, a third aspect of an embodiment of the present application proposes an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the RPKI-based routing data anomaly detection method as described in the first aspect is implemented.

[0039] To achieve the above-mentioned purpose, the fourth aspect of an embodiment of the present application proposes a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, it implements the RPKI-based routing data anomaly detection method described in the first aspect above.

[0040] The embodiments of the present application propose a method and related equipment for detecting anomalies in routing data based on RPKI, which include: first, obtaining routing origin data from real-time gateway data; then, performing resource public key infrastructure technology analysis on the routing origin data to obtain a resource public key infrastructure technology analysis result; then, when the resource public key infrastructure technology analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology, performing gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result; thereafter, when the resource public key infrastructure technology analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, performing routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result, and performing routing origin authorization anomaly detection on the routing origin data again after a preset detection period; finally, based on the gateway prefix anomaly detection result or the routing anomaly detection result, obtaining assertion replacement data corresponding to the routing origin data, and repairing the routing origin data based on the assertion replacement data. In an embodiment of the present application, resource public key infrastructure technology analysis is performed on the routing origin data in the real-time gateway data to determine whether the real-time gateway data can support the resource public key infrastructure technology, so as to facilitate further corresponding anomaly detection, and periodic detection is performed on the routing origin data that can support the resource public key infrastructure technology, thereby improving the accuracy of routing origin authorization anomaly detection for gateway data, and using reliable assertion replacement data corresponding to the routing origin data to replace the abnormal routing origin data, thereby improving the accuracy and reliability of repairing the abnormal gateway data.

[0041] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purposes and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 This is a schematic diagram of a resource public key infrastructure provided by an embodiment of the present application.

[0043] Figure 2 This is a structural diagram of a gateway data anomaly detection system provided by another embodiment of the present application.

[0044] Figure 3 This is a flowchart of a method for detecting anomalies in routing data based on RPKI provided in another embodiment of the present application.

[0045] Figure 4 yes Figure 3 Flowchart of step 302 in FIG.

[0046] Figure 5 yes Figure 3 Flowchart of step 303 in FIG.

[0047] Figure 6 yes Figure 3 Flowchart of step 304 in FIG.

[0048] Figure 7 yes Figure 6 Flowchart of step 602 in FIG.

[0049] Figure 8 This is a flowchart of performing routing origin authorization anomaly detection again provided by another embodiment of the present application.

[0050] Figure 9 yes Figure 3 Flowchart of step 305 in FIG.

[0051] Figure 10 This is a flowchart of repairing abnormal gateway data provided by another embodiment of the present application.

[0052] Figure 11 This is a flowchart of a method for detecting anomalies in routing data based on RPKI, provided in another embodiment of the present application.

[0053] Figure 12 This is a structural diagram of a routing data anomaly detection device based on RPKI provided in another embodiment of the present application.

[0054] Figure 13 This is a schematic diagram of the hardware structure of an electronic device provided in another embodiment of the present application. DETAILED DESCRIPTION

[0055] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0056] It should be noted that although the functional modules are divided in the device schematic and the logical order is shown in the flowchart, in some cases, the steps shown or described can be performed in a different order than the module division in the device or the order in the flowchart.

[0057] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.

[0058] First, let’s analyze some of the terms used in this application:

[0059] AS: Autonomous System. On the Internet, an autonomous system (AS) is a small unit that has the authority to independently determine the routing protocols used within the system. This network unit can be a simple network or a group of networks controlled by one or more common network administrators. It is a separately manageable network unit (such as a university, an enterprise, or an individual company). An autonomous system is sometimes also called a routing domain. An autonomous system is assigned a globally unique 16-bit number, sometimes called an autonomous system number (ASN).

[0060] RPKI (Resource Public Key Infrastructure) is a framework used by ISPs to verify the origin and path of BGP routes. Developed to combat the increasing frequency and severity of internet route hijacking incidents, RPKI helps routers verify the authenticity of BGP messages by issuing and authenticating a specific X.509 digital certificate and digital signature format, thereby enhancing BGP protocol security and helping prevent internet route hijacking. The fundamental concept of RPKI is to build a PKI (Public Key Infrastructure) to authenticate the ownership and use of IP address prefixes and AS numbers.

[0061] SLURM (Simplified Local Internet Number Resource Management) allows operators to create a global RPKI assertion set for provenance verification in JSON format. The RPKI provenance verification data is split into two parts: one part comes from the RPKI repository, and the other part comes from the data in the SLURM file.

[0062] BGP (Border Gateway Protocol) is a network protocol running on TCP, mainly used to exchange routing information between network autonomous systems in order to determine efficient routing and realize information packet transmission in the Internet.

[0063] Route Origin Authorization (ROA) is a network security mechanism used to improve the security of Internet routing. As part of the RPKI system, ROA completes the authentication and binding of IP addresses and prefix resources. It is essentially a digital signature object that allows anyone to verify whether the IP address block holder has authorized the AS relationship.

[0064] RP (RPKI Rely), also known as the RPKI relying party, is essentially an RPKI validator. It synchronizes the certificate data in the RPKI database and verifies the signature, and sends a batch of verified ROA data to the BGP router. After BGP synchronizes this data, it can be used as a trusted data for route filtering to prevent the risk of prefix hijacking.

[0065] Reference Figure 1 , is a schematic diagram of a resource public key infrastructure provided by an embodiment of this application. Figure 1 As shown in , the resource public key infrastructure usually includes multiple certificate management units (such as Figure 1 The RPKI relies on a certificate issuance system consisting of multiple autonomous systems (ASs) such as APNIC, CNNIC, and ISPs, and a certificate storage system for storing the certificate resources of each certificate management unit (including the storage database corresponding to each certificate management unit, such as the APNIC database corresponding to APNIC). In addition, during the certificate resource issuance process, RPKI relying parties will also synchronize these certificate resource data to facilitate the transmission of authentication data to the autonomous system composed of multiple ASs for authentication during the resource use process, and the use of corresponding network resources after authentication is passed.

[0066] By using Resource Public Key Infrastructure (RPKI), network operators can verify the legitimacy of routing information received from other network operators and reject untrusted routes. This helps reduce the risk of route hijacking and spoofing attacks and improves the security and stability of the Internet routing system. It's important to note that RPKI is a complex system that requires the cooperation of network operators, Internet service providers, and other stakeholders for effective deployment and operation. It plays a critical role in protecting the Internet routing system from malicious attacks.

[0067] When RPKI-reliant parties or network devices use network resources, a series of gateway data will be generated. In order to improve network security, gateway data anomaly detection is usually required.

[0068] Routing origin authorization anomaly detection is a key method for ensuring data security within a network framework that supports resource public key infrastructure (RPKI). It is often combined with gateway data anomaly detection. During network communications, data flows through the gateway are monitored and analyzed to identify and flag data points or events that support RPKI and do not conform to normal behavior patterns. This process is crucial for maintaining network instability and stability by helping to promptly identify potential security threats, system failures, or other abnormal behavior.

[0069] In related technologies, routing origin authorization anomaly detection for gateway data typically involves pre-emptive anomaly allocation detection of resource-related data in the public key infrastructure (RPKI). The anomaly detection status is then analyzed based on the results. However, due to the diverse nature of routing origin authorization anomaly detection, pre-emptive anomaly detection alone cannot quickly and accurately determine the actual routing origin authorization status of gateway data during RPKI use, and thus cannot perform corresponding remediation.

[0070] In order to improve the accuracy of routing origin authorization detection of gateway data and improve the reliability of repairing abnormal gateway data, in an embodiment of the present application, resource public key infrastructure technology analysis is performed on the routing origin data in the real-time gateway data to determine whether the real-time gateway data can support resource public key infrastructure technology, so as to facilitate further corresponding anomaly detection, and periodic detection is performed on the routing origin data that can support resource public key infrastructure technology, thereby improving the accuracy of routing origin authorization anomaly detection of gateway data, and using reliable assertion replacement data corresponding to the routing origin data to replace the abnormal routing origin data, thereby improving the accuracy and reliability of repairing the abnormal gateway data.

[0071] The following will further describe the RPKI-based routing data anomaly detection method and related devices provided by the embodiment of the present application. In order to better illustrate the RPKI-based routing data anomaly detection method provided by the embodiment of the present application, this embodiment first describes a gateway data anomaly detection system of the present application. Figure 2 As shown in FIG, it is a schematic diagram of the structure of a gateway data anomaly detection system provided by an embodiment of the present application. Figure 2 As shown in [1], the gateway data anomaly detection system includes an RPKI subscription module, an RPKI detection module, and an RPKI assurance module. The RPKI subscription module is used to obtain BGP flow data (i.e., gateway data) and related data from the RPKI database in real time. The RPKI monitoring module then uses trusted BGP data to monitor the BGP flow data for anomalies. When anomalies are found in the BGP flow data, the trusted RPKI data is used to repair the anomaly in the RPKI assurance module, thereby achieving automated gateway data anomaly detection and repair.

[0072] Among them, BGP flow data: provides BGP real-time data flow services and provides a data source for BGP data monitoring. RPKI database: provides a real-time RPKI monitoring data source. RPKI subscription module: provides a code resource subscription service, which can focus on monitoring designated code resources and pay attention to changes in code resources in the subscription list. RPKI monitoring module provides BGP and RPKI data change monitoring, and analyzes information such as abnormal events. Trusted BGP data: A trusted BGP authoritative data containing information such as prefixes and AS numbers. The RPKI monitoring module uses trusted BGP data as the basis for determining BGP prefix hijacking events, providing authoritative support for determining prefix hijacking. The RPKI assurance module is essentially an RP-relying party configuring local policies based on SLURM files to repair changed data. Trusted RPKI data defines another authoritative data in addition to the RPKI database, providing trusted data support for the RPKI assurance module to formulate SLURM repair files.

[0073] based on Figure 2 The gateway data anomaly detection system shown in the figure will be described in detail below. The routing data anomaly detection method based on RPKI in the embodiment of the present application is applied to the gateway data anomaly detection system, which can be set up in any server or network processor, etc.

[0074] Reference Figure 3 , which is an optional flowchart of the RPKI-based routing data anomaly detection method provided in an embodiment of the present application, Figure 3 The method may include but is not limited to steps 301 to 305. It is also understood that this embodiment is for Figure 3 The order of step 301 to step 305 is not specifically limited, and the order of steps can be adjusted or some steps can be reduced or added according to actual needs.

[0075] Step 301: Obtain routing origin data from real-time gateway data.

[0076] Step 301 is described in detail below.

[0077] In some embodiments, in response to anomaly detection of gateway data, real-time gateway data (i.e., BGP flow information) generated by executing the Border Gateway Protocol (BGP) is obtained from the network system in real time, and then the required route origin data is obtained from this real-time gateway data. It is understood that the route origin data generally includes the IP address prefix information, autonomous system number (AS number), etc. of the BGP flow information, thereby facilitating the subsequent use of this route origin data to perform anomaly detection on the real-time gateway data, thereby improving the security of the network system.

[0078] Step 302: Perform resource public key infrastructure technical analysis on the routing origin data to obtain a resource public key infrastructure technical analysis result.

[0079] Step 302 is described in detail below.

[0080] In some embodiments, after obtaining the routing origin data, in order to accurately detect anomalies, it is necessary to first perform Resource Public Key Infrastructure (RPKI) analysis on it to determine whether the real-time gateway data supports Resource Public Key Infrastructure (RPKI) technology. This facilitates subsequent anomaly detection analysis based on the obtained RPKI analysis results. The following further describes how to perform RPKI analysis.

[0081] Reference Figure 4 , performing resource public key infrastructure technology analysis on the routing origin data to obtain the resource public key infrastructure technology analysis result, including the following steps 401 to 402.

[0082] Step 401: Obtain the target code number identifier corresponding to the routing origin data.

[0083] Step 402: Match the target code number identifier with multiple code number identifiers in the resource public key infrastructure database, and obtain a resource public key infrastructure technical analysis result based on the matching result.

[0084] Steps 401 to 402 are described in detail below.

[0085] In some embodiments, after obtaining the routing origin data, first obtain the corresponding target code number identifier (i.e., the corresponding IP prefix information and AS number) from the routing origin data. Then, obtain the target code number identifier from the resource public key infrastructure database (i.e., Figure 2 The RPKI database shown in the figure matches multiple RPKI data information (including code number identifiers and associated routing origin authorization ROA data corresponding to the RPKI data information) stored in the RPKI database, that is, the target code number identifier is matched with the code number identifiers corresponding to the multiple RPKI data information; if a match is obtained, it means that the routing origin data corresponding to the real-time gateway data has corresponding ROA data, and can support resource public key infrastructure technology; if no match is found, it means that the routing origin data corresponding to the real-time gateway data does not have corresponding ROA data, and cannot support resource public key infrastructure technology, and then the corresponding resource public key infrastructure technology analysis result is generated according to the actual matching result.

[0086] Through the above steps 401 to 402, by matching the code number identifiers corresponding to multiple RPKI data information in the resource public key infrastructure database with the target code number identifiers corresponding to the implementation code number data, it is possible to quickly and accurately determine whether the routing origin data supports the resource public key infrastructure technology analysis results of the resource public key technology facility technology, thereby facilitating subsequent corresponding anomaly detection based on different resource public key infrastructure technology analysis results to improve the accuracy of gateway data anomaly detection.

[0087] Step 303: When the resource public key infrastructure technology analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology, a gateway prefix hijacking detection is performed on the routing origin data to obtain a gateway prefix anomaly detection result.

[0088] Step 303 is described in detail below.

[0089] In some embodiments, when the resource public key infrastructure technology analysis result obtained indicates that there is no code number identifier corresponding to the target code number identifier in the routing origin data in the resource public key infrastructure database, it means that the routing origin data does not support the resource public key infrastructure technology. At this time, the routing origin data will be subjected to a Border Gateway Protocol (BGP) anomaly detection to obtain a gateway prefix anomaly detection result corresponding to this situation, as described below.

[0090] Reference Figure 5 , performing gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result, including the following steps 501 to 502.

[0091] Step 501: Obtain routing origin data from real-time gateway data.

[0092] Step 502: Match the route origin data with the authoritative data in the Internet resource database to obtain a gateway prefix anomaly detection result.

[0093] Steps 501 to 502 are described in detail below.

[0094] In some embodiments, when the resource public key infrastructure technology analysis result indicates that the route origin data does not support the resource public key infrastructure technology, the route origin data (i.e., IP address prefix data) is obtained from the real-time gateway data. Then, a trusted Internet resource database (such as whois, etc.) is used to monitor and analyze the BGP routing information of the real-time gateway data, that is, the route origin data is matched with all authoritative data in the Internet resource database to determine whether the route origin data can be completely matched with a certain authoritative data. Then, based on the matching result, a gateway prefix anomaly detection result is obtained to determine whether a suspected BGP hijacking incident has occurred. That is, by comparing the AS autonomous system to which the prefix belongs with a piece of authoritative data, if the AS number to which the prefix belongs in the BGP data is different from the AS number of the authoritative data (non-path match), it is considered a prefix hijacking incident.

[0095] Through the above steps 501 to 502, in the case where the routing origin data does not support resource public key infrastructure technology, the code prefix data corresponding to the routing origin data is matched and detected using a trusted Internet resource database, so that the gateway prefix anomaly detection result in this case can be accurately obtained, thereby improving the accuracy of gateway data anomaly detection.

[0096] Step 304: When the resource public key infrastructure technology analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, a routing origin authorization anomaly detection is performed on the routing origin data to obtain a routing anomaly detection result, and a routing origin authorization anomaly detection is performed on the routing origin data again after a preset detection period.

[0097] Step 304 is described in detail below.

[0098] In some embodiments, when the resource public key infrastructure technology analysis result obtained indicates that there is a code number identifier corresponding to the target code number identifier in the routing origin data in the resource public key infrastructure database, it means that the routing origin data supports the resource public key infrastructure technology. At this time, the routing origin data will be subjected to routing origin authorization ROA anomaly detection to obtain the corresponding routing anomaly detection result, as described below.

[0099] Reference Figure 6 , performing routing origin authorization anomaly detection on routing origin data to obtain routing anomaly detection results, including the following steps 601 to 603.

[0100] Step 601: Obtain routing origin authorization data of real-time gateway data and the number of routing origin authorization data corresponding to the routing origin authorization data.

[0101] Step 602: When there are multiple routing origin authorization data, perform attribution association detection on the multiple routing origin authorization data to obtain a routing anomaly detection result.

[0102] Steps 601 to 602 are described in detail below.

[0103] In some embodiments, when the resource public key infrastructure technology analysis result indicates that the routing origin data supports the resource public key infrastructure technology, all routing origin authorization data (i.e., ROA data) and the corresponding number of ROA data (i.e., the number of routing origin authorization data) of the real-time gateway data are first obtained.

[0104] When it is determined that there are multiple routing origin authorization data, attribution association detection is performed on the multiple routing origin authorization data to obtain corresponding routing anomaly detection results, which are described in detail below.

[0105] Reference Figure 7 , performing attribution association detection on multiple routing origin authorization data to obtain routing anomaly detection results, including the following steps 701 to 703.

[0106] Step 701: Obtain the authorization agency of each routing origin authorization data, and obtain the agency association chain of each authorization agency.

[0107] Step 702: When all authorized institutions belong to the same institution association chain, a routing origin authorization change detection is performed on multiple routing origin authorization data to obtain a routing anomaly detection result.

[0108] Step 703: When there are at least two authorized institutions that do not belong to the same institution association chain, a routing anomaly detection result is generated to indicate that there is an anomaly in the routing origin data.

[0109] Steps 701 to 703 are described in detail below.

[0110] In some embodiments, when it is determined that the number of routing origin authorization data corresponding to the real-time gateway data is multiple, a conflict detection is performed on the multiple routing origin authorization data to obtain the corresponding routing anomaly detection result. Specifically, the authorization agency corresponding to each routing origin authorization data is obtained, and the agency association chain corresponding to each authorization agency is obtained (such as Figure 1In the APNIC-CNNIC-SIP-AS2 shown in Figure 2, when all authorized institutions belong to the same institution association chain, it means that these multiple routing origin authorization data are associated in the same institution relationship chain, which means they are compliant. At this point, routing origin authorization change detection is further performed on these multiple routing origin authorization data to detect whether the routing origin authorization data (ROA data) has changed, that is, whether the AS value of the prefix data corresponding to the routing origin authorization data has changed. If so, it is determined that a suspected ROA tampering event has occurred in this real-time gateway data. Conversely, if no change has occurred, it is determined that this real-time gateway data is normal. Based on the corresponding change situation, the corresponding routing anomaly detection result is generated.

[0111] When there are at least two authorized agencies that do not belong to the same agency association chain, it means that the authorized agencies in different agency relationship chains have performed conflicting processing on the real-time gateway data. This is non-compliant and will be identified as a suspected ROA injection event, and a routing anomaly detection result will be generated to characterize the abnormality of the routing origin data.

[0112] Step 603: When the number of the routing origin authorization data is one, perform routing origin authorization change detection on the routing origin authorization data to obtain a routing anomaly detection result.

[0113] Step 603 is described in detail below.

[0114] In some embodiments, when the number of routing origin authorization data is one, a routing origin authorization change detection is directly performed on the routing origin authorization data, that is, whether the routing origin authorization data (ROA data) has changed, that is, whether the AS value of the prefix data corresponding to the routing origin authorization data has changed. If a change has occurred, it is determined that a suspected ROA tampering event has occurred in the real-time gateway data; correspondingly, if no change has occurred, it is determined that the real-time gateway data is normal, and thus a corresponding routing anomaly detection result is generated based on the corresponding change situation.

[0115] Through the above steps 601 to 603 and 701 to 703, for the case where the routing origin data supports the resource public key infrastructure technology, and for the case where the number of routing origin authorization data corresponding to the real-time gateway data is multiple, conflict detection is performed to determine whether an abnormal situation of ROA injection has occurred, and then the routing origin authorization data is further subjected to routing origin authorization change detection to determine whether a suspected ROA tampering event has occurred, thereby performing corresponding detection and judgment according to different situations, thereby obtaining accurate routing anomaly detection results.

[0116] In some embodiments, in the case where routing origin data supports resource public key infrastructure technology, in order to further improve the accuracy of gateway data anomaly detection, after performing routing origin authorization anomaly detection on real-time gateway data, routing origin authorization anomaly detection is performed again on the routing origin data after a preset period, as described below.

[0117] Reference Figure 8 After the routing origin authorization anomaly detection is performed again on the routing origin data after the preset detection period, the routing data anomaly detection method based on RPKI further includes the following steps 801 to 802.

[0118] Step 801: When the routing origin authorization data corresponding to the routing origin data cannot be detected, a revocation matching result is obtained by matching multiple code number identifiers in the routing certificate revocation list based on the target code number identifier.

[0119] Step 802: Based on the revocation matching result, a routing anomaly detection result is generated for characterizing anomalies in routing origin authorization data.

[0120] Steps 801 to 802 are described in detail below.

[0121] In some embodiments, after the routing origin data is again detected for routing origin authorization anomalies after a preset detection period, if the routing origin authorization data (ROA data) corresponding to the original routing origin data cannot be detected, multiple recent ROA revocation data information from the routing certificate revocation list in the resource public key facility database will be matched, that is, the target code number identifier corresponding to the real-time gateway data will be matched with the code number identifiers corresponding to the multiple ROA revocation data information to obtain a revocation matching result.

[0122] When the revocation matching result indicates that a code number identifier that matches the target code number identifier exists in the certificate revocation list, it indicates that the route origin authorization data (ROA data) has been revoked. In this case, it is determined that a suspected ROA revocation event has occurred, and a route anomaly detection result is generated to indicate that the route origin authorization data is abnormal. When the revocation matching result indicates that a code number identifier that matches the target code number identifier does not exist in the certificate revocation list, it indicates that an abnormality has occurred in the route origin authorization data (ROA data). In this case, it is determined that a suspected ROA deletion / destruction / suppression event has occurred, and a route anomaly detection result is generated to indicate that the route origin authorization data is abnormal.

[0123] Through the above steps 801 to 802, the routing origin data supports resource public key infrastructure technology and performs repeated detection, and if the routing origin authorization data disappears, the certificate revocation list is used for detection and matching to accurately obtain the routing anomaly detection result corresponding to the situation, thereby improving the accuracy of gateway data anomaly detection.

[0124] Step 305: Based on the gateway prefix anomaly detection result or the route anomaly detection result, obtain assertion replacement data corresponding to the route origin data, and repair the route origin data based on the assertion replacement data.

[0125] Step 305 is described in detail below.

[0126] In some embodiments, after performing corresponding gateway prefix hijacking detection or routing origin authorization anomaly detection on the real-time gateway data based on the resource public key infrastructure technology analysis results to obtain the corresponding gateway prefix anomaly detection result or routing anomaly detection result, when the gateway prefix anomaly detection result or routing anomaly detection result indicates that an abnormal situation has occurred in the real-time gateway data, in order to improve the security and reliability of the network system, it is necessary to obtain assertion replacement data corresponding to the routing origin data, and repair the routing origin data based on the assertion replacement data, as described below.

[0127] Reference Figure 9 , based on the gateway prefix anomaly detection result or the routing anomaly detection result, obtaining the assertion replacement data corresponding to the routing origin data, and repairing the routing origin data based on the assertion replacement data, including the following steps 901 to 903.

[0128] Step 901: When the gateway prefix anomaly detection result or the route anomaly detection result indicates that the route origin data is abnormal, prefix data filtering is performed on the real-time gateway data to obtain filtered code number data.

[0129] Step 902: Obtain assertion replacement data corresponding to the filter code number data from the authoritative database.

[0130] Step 903: Replace the resource public key data information corresponding to the real-time gateway data in the resource public key infrastructure database based on the assertion replacement data.

[0131] Steps 901 to 903 are described in detail below.

[0132] In some embodiments, when the gateway prefix anomaly detection result or the route anomaly detection result indicates that the origin data of the route is abnormal, the SLURM strategy can be used for repair. The repair data of the SLURM strategy comes from a third-party trusted authoritative database (e.g., Figure 2The trusted RPKI data shown in the is used to generate a SLURM file based on this authoritative database and deploy it to the RP-side relying party to repair these abnormal data events. Specifically, prefix data filtering is performed on the routing origin data corresponding to the real-time gateway data to filter out the prefix data of the real-time gateway data and obtain the filter code data of the fixed data in the remaining real-time gateway data. Then, the assertion replacement data corresponding to the filter code data is obtained from the authoritative database of a third party, and then the corresponding SLURM file is generated based on the assertion replacement data. The resource public key data information corresponding to the original real-time gateway data in the resource public key infrastructure database is replaced based on the SLURM file to implement the repair process.

[0133] Reference Figure 10 , is a flow chart of repairing abnormal gateway data provided by an embodiment of the present application. Figure 10 As shown in , the specific guarantee process for abnormal real-time gateway data is as follows: SLURM data consists of two parts: filtering data and assertion data. A set of filtering data is generated based on the code resources that need to be repaired (i.e., abnormal real-time gateway data), and a corresponding set of assertion data is generated based on local authoritative data. Then, a SLURM policy file in JSON format is generated according to the SLURM policy generation module and uploaded to the RPKI relying party. In addition to synchronizing the database data, the RPKI relying party filters the data according to the SLURM file and replaces the code resources in the database with the assertion data in SLURM. Then, a set of trusted data is compiled and provided to the BGP autonomous system to complete the repair process here.

[0134] Through the above steps 901 to 903, local authoritative data is used to generate assertion replacement data corresponding to the real-time gateway data with anomalies, and direct replacement repair is performed without the need for a complex process of targeted repair for different abnormal situations, thereby improving the efficiency of gateway data anomaly repair and improving the security and reliability of the gateway data transmission process.

[0135] Reference Figure 11 , is a schematic flow chart of a method for detecting anomalies in routing data based on RPKI provided in an embodiment of the present application. Figure 11As shown in [1], the gateway data anomaly detection system obtains BGP flow information (i.e., real-time gateway data) in real time through resource subscriptions. It then performs RPKI parsing to determine whether there is ROA data. If ROA data does not exist, it indicates that the BGP flow information does not support resource public key infrastructure technology. At this time, prefix hijacking detection is performed on it, and the corresponding anomaly detection result is obtained. If ROA data exists, it indicates that the BGP flow information does support resource public key infrastructure technology. At this time, it further determines whether there are multiple ROA data. If multiple ROA data do exist, conflict detection is first performed to obtain the corresponding conflict detection result. If only one ROA data exists or the conflict detection result indicates that it is correct, ROA changes are further detected. If the ROA changes, a corresponding anomaly detection result is generated. If the ROA disappears, a CRL list query is used to obtain the corresponding anomaly detection result. Finally, local authoritative data is used to generate assertion replacement data corresponding to the abnormal BGP flow information for ALURM repair, ensuring the security and reliability of the network system.

[0136] The embodiment of the present application proposes a method and related equipment for detecting anomalies in routing data based on RPKI, and the method includes: first, obtaining routing origin data from real-time gateway data; then, obtaining a target code number identifier corresponding to the routing origin data, matching the target code number identifier with multiple code number identifiers in the resource public key infrastructure database, and obtaining a resource public key infrastructure technical analysis result based on the matching result, wherein the code number identifier is associated with routing origin authorization data; then, when the resource public key infrastructure technical analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology, obtaining routing origin data from the real-time gateway data, matching the routing origin data with the authoritative data in the Internet resource database, and obtaining a gateway prefix anomaly detection result; thereafter, when the resource public key infrastructure technical analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, obtaining routing origin authorization data of the real-time gateway data and the number of routing origin authorization data corresponding to the routing origin authorization data, and when the number of routing origin authorization data is multiple, obtaining the authorization agency of each routing origin authorization data, and obtaining the agency association chain of each authorization agency, when all authorization agencies belong to the same agency association chain. In the chain, a routing origin authorization change detection is performed on multiple routing origin authorization data to obtain a routing anomaly detection result. When there are at least two authorization institutions that do not belong to the same institution association chain, a routing anomaly detection result is generated to characterize the existence of an anomaly in the routing origin data. When the number of routing origin authorization data is one, a routing origin authorization change detection is performed on the routing origin authorization data to obtain a routing anomaly detection result. After a preset detection period, a routing origin authorization anomaly detection is performed on the routing origin data again. When the routing origin authorization data corresponding to the routing origin data cannot be detected, a plurality of code number identifiers are matched from the routing certificate revocation list based on the target code number identifier to obtain a revocation matching result. Based on the revocation matching result, a routing anomaly detection result is generated to characterize the anomaly of the routing origin authorization data. Finally, when the gateway prefix anomaly detection result or the routing anomaly detection result characterizes that the routing origin data is anomaly, prefix data filtering is performed on the real-time gateway data to obtain filtered code number data, and assertion replacement data corresponding to the filtered code number data is obtained from the authoritative database. The resource public key data information corresponding to the real-time gateway data in the resource public key infrastructure database is replaced based on the assertion replacement data.

[0137] In an embodiment of the present application, by matching the code number identifiers corresponding to multiple RPKI data information in the resource public key infrastructure database with the target code number identifiers corresponding to the implementation code number data, it is possible to quickly and accurately determine whether the routing origin data supports the resource public key infrastructure technology facility technology resource public key infrastructure technical analysis results, thereby facilitating subsequent corresponding anomaly detection based on different resource public key infrastructure technical analysis results to improve the accuracy of gateway data anomaly detection; and, for the case where the routing origin data does not support the resource public key infrastructure technology, a trusted Internet resource database is used to match and detect the code number prefix data corresponding to the routing origin data and the autonomous system path, so that the gateway prefix anomaly detection result in this case can be accurately obtained, thereby improving the accuracy of gateway data anomaly detection; and, for the case where the routing origin data supports the resource public key infrastructure technology, conflict detection is performed when there are multiple routing origin authorization data corresponding to the real-time gateway data to determine whether an ROA injection anomaly has occurred, and then routing origin authorization change detection is further performed on the routing origin authorization data to determine whether a suspected ROA tampering event has occurred, thereby performing corresponding detection and judgment according to different situations. Thus, accurate routing anomaly detection results are obtained; in addition, when the routing origin data supports resource public key infrastructure technology and performs repeated detection, and the routing origin authorization data disappears, the certificate revocation list is used for detection and matching to accurately obtain routing anomaly detection results corresponding to the situation, thereby improving the accuracy of gateway data anomaly detection; in addition, local authoritative data is used to generate assertion replacement data corresponding to the real-time gateway data with anomalies, and replacement and repair are directly performed without the need for a complex process of targeted repair for different anomalies, thereby improving the efficiency of gateway data anomaly repair and improving the security and reliability of the gateway data transmission process; in short, the routing origin data in the real-time gateway data is parsed by resource public key infrastructure technology to determine whether the real-time gateway data can support resource public key infrastructure technology, so as to further perform corresponding anomaly detection, and periodically detect the routing origin data that can support resource public key infrastructure technology, thereby improving the accuracy of gateway data anomaly detection, and using reliable assertion replacement data corresponding to the routing origin data to replace the routing origin data with anomalies, thereby improving the accuracy and reliability of the repair of the anomaly gateway data.

[0138] The embodiment of the present application also provides a routing data anomaly detection device based on RPKI, which can implement the above-mentioned routing data anomaly detection method based on RPKI, referring to Figure 12 , the apparatus 1200 comprises:

[0139] The code number data acquisition module 1210 is used to obtain routing origin data from real-time gateway data;

[0140] The resource technology analysis module 1220 is used to perform resource public key infrastructure technology analysis on the routing origin data to obtain a resource public key infrastructure technology analysis result;

[0141] The gateway anomaly detection module 1230 is configured to perform a gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result when the resource public key infrastructure technology analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology;

[0142] The routing detection module 1240 is configured to perform routing origin authorization anomaly detection on the routing origin data when the resource public key infrastructure technology analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, obtain a routing anomaly detection result, and perform routing origin authorization anomaly detection on the routing origin data again after a preset detection period;

[0143] The repair module 1250 is configured to obtain assertion replacement data corresponding to the route origin data based on the gateway prefix anomaly detection result or the route anomaly detection result, and repair the route origin data based on the assertion replacement data.

[0144] In some embodiments, the resource technology parsing module 1220 is further configured to:

[0145] Obtain the target code number identifier corresponding to the routing origin data;

[0146] Based on matching the target code number identifier with multiple code number identifiers in the resource public key infrastructure database, and obtaining the resource public key infrastructure technical analysis result based on the matching result, the code number identifier is associated with the routing origin authorization data.

[0147] In some embodiments, the gateway anomaly detection module 1230 is further configured to:

[0148] Obtain route origin data from real-time gateway data;

[0149] The routing origin data is matched with the authoritative data in the Internet resource database to obtain the gateway prefix anomaly detection results.

[0150] In some embodiments, the route detection module 1240 is further configured to:

[0151] Obtain routing origin authorization data of routing origin data and the number of routing origin authorization data corresponding to the routing origin authorization data;

[0152] When there are multiple routing origin authorization data, perform attribution association detection on the multiple routing origin authorization data to obtain routing anomaly detection results;

[0153] When the number of routing origin authorization data is one, routing origin authorization change detection is performed on the routing origin authorization data to obtain a routing anomaly detection result.

[0154] In some embodiments, the route detection module 1240 is further configured to:

[0155] Obtain the authority of each route origin authorization data and the authority association chain of each authority;

[0156] When all authorized institutions belong to the same institution association chain, the routing origin authorization change detection is performed on multiple routing origin authorization data to obtain routing anomaly detection results;

[0157] When there are at least two authorized institutions that do not belong to the same institution association chain, a routing anomaly detection result is generated to indicate that there is an anomaly in routing origin data.

[0158] In some embodiments, the route detection module 1240 is further configured to:

[0159] When the routing origin authorization data corresponding to the routing origin data cannot be detected, matching multiple code number identifiers from the routing certificate revocation list based on the target code number identifier to obtain a revocation matching result;

[0160] Based on the revocation matching result, a routing anomaly detection result is generated for characterizing anomalies in routing origin authorization data.

[0161] In some embodiments, the repair module 1250 is further configured to:

[0162] When the gateway prefix anomaly detection result or the route anomaly detection result indicates that the route origin data is abnormal, the real-time gateway data is prefix filtered to obtain the filtered code number data;

[0163] Obtain assertion replacement data corresponding to the filter code number data from the authoritative database;

[0164] The resource public key data information corresponding to the real-time gateway data in the resource public key infrastructure database is replaced based on the assertion replacement data.

[0165] In the above embodiments, the description of each embodiment has its own focus. For the part that is not described in detail in a certain embodiment, the specific implementation of the RPKI-based routing data anomaly detection device is basically the same as the specific implementation of the RPKI-based routing data anomaly detection method, and will not be repeated here.

[0166] In an embodiment of the present application, by matching the code number identifiers corresponding to multiple RPKI data information in the resource public key infrastructure database with the target code number identifiers corresponding to the implementation code number data, it is possible to quickly and accurately determine whether the routing origin data supports the resource public key infrastructure technology facility technology resource public key infrastructure technical analysis results, thereby facilitating subsequent corresponding anomaly detection based on different resource public key infrastructure technical analysis results to improve the accuracy of gateway data anomaly detection; and, for the case where the routing origin data does not support the resource public key infrastructure technology, a trusted Internet resource database is used to match and detect the code number prefix data corresponding to the routing origin data and the autonomous system path, so that the gateway prefix anomaly detection result in this case can be accurately obtained, thereby improving the accuracy of gateway data anomaly detection; and, for the case where the routing origin data supports the resource public key infrastructure technology, conflict detection is performed when there are multiple routing origin authorization data corresponding to the real-time gateway data to determine whether an ROA injection anomaly has occurred, and then routing origin authorization change detection is further performed on the routing origin authorization data to determine whether a suspected ROA tampering event has occurred, thereby performing corresponding detection and judgment according to different situations. Thus, accurate routing anomaly detection results are obtained; in addition, when the routing origin data supports resource public key infrastructure technology and performs repeated detection, and the routing origin authorization data disappears, the certificate revocation list is used for detection and matching to accurately obtain routing anomaly detection results corresponding to the situation, thereby improving the accuracy of gateway data anomaly detection; in addition, local authoritative data is used to generate assertion replacement data corresponding to the real-time gateway data with anomalies, and replacement and repair are directly performed without the need for a complex process of targeted repair for different anomalies, thereby improving the efficiency of gateway data anomaly repair and improving the security and reliability of the gateway data transmission process; in short, the routing origin data in the real-time gateway data is parsed by resource public key infrastructure technology to determine whether the real-time gateway data can support resource public key infrastructure technology, so as to further perform corresponding anomaly detection, and periodically detect the routing origin data that can support resource public key infrastructure technology, thereby improving the accuracy of gateway data anomaly detection, and using reliable assertion replacement data corresponding to the routing origin data to replace the routing origin data with anomalies, thereby improving the accuracy and reliability of the repair of the anomaly gateway data.

[0167] An embodiment of the present application further provides an electronic device, including:

[0168] at least one memory;

[0169] at least one processor;

[0170] at least one program;

[0171] The program is stored in the memory, and the processor executes the at least one program to implement the above-mentioned RPKI-based routing data anomaly detection method implemented in this application. The electronic device can be any smart terminal including a mobile phone, a tablet computer, a personal digital assistant (PDA), an in-vehicle computer, etc.

[0172] See also Figure 13 , Figure 13 The hardware structure of an electronic device according to another embodiment is shown. The electronic device includes:

[0173] The processor 1301 can be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;

[0174] The memory 1302 can be implemented in the form of ROM (Read Only Memory), static storage device, dynamic storage device or RAM (Random Access Memory). The memory 1302 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1302 and is called by the processor 1301 to execute the RPKI-based routing data anomaly detection method of the embodiment of the present application;

[0175] Input / output interface 1303, used to implement information input and output;

[0176] Communication interface 1304, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);

[0177] Bus 1305 , which transmits information between various components of the device (e.g., processor 1301 , memory 1302 , input / output interface 1303 , and communication interface 1304 );

[0178] The processor 1301 , the memory 1302 , the input / output interface 1303 and the communication interface 1304 are connected to each other in communication within the device via a bus 1305 .

[0179] An embodiment of the present application further provides a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, the above-mentioned RPKI-based routing data anomaly detection method is implemented.

[0180] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0181] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0182] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0183] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0184] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.

[0185] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0186] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0187] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0188] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0189] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0190] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0191] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.

Claims

1. A method for detecting anomalies in routing data based on RPKI, characterized in that: The method comprises: Obtain route origin data from real-time gateway data; Performing resource public key infrastructure technical analysis on the routing origin data to obtain a resource public key infrastructure technical analysis result; When the resource public key infrastructure technology analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology, performing a gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result; When the resource public key infrastructure technology analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, performing a routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result, and performing the routing origin authorization anomaly detection on the routing origin data again after a preset detection period; Based on the gateway prefix anomaly detection result or the routing anomaly detection result, assertion replacement data corresponding to the routing origin data is acquired, and the routing origin data is repaired based on the assertion replacement data.

2. The RPKI-based routing data anomaly detection method according to claim 1, characterized in that: The performing resource public key infrastructure technical analysis on the routing origin data to obtain a resource public key infrastructure technical analysis result includes: Obtaining a target code number identifier corresponding to the routing origin data; The target code number identifier is matched with a plurality of code number identifiers in a resource public key infrastructure database, and the resource public key infrastructure technical analysis result is obtained based on the matching result, wherein the code number identifier is associated with routing origin authorization data.

3. The RPKI-based routing data anomaly detection method according to claim 1, characterized in that: The performing gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result includes: Obtaining routing origin data from the real-time gateway data; The routing origin data is matched with the authoritative data in the Internet resource database to obtain the aforementioned gateway prefix anomaly detection result.

4. The RPKI-based routing data anomaly detection method according to claim 1, characterized in that: The performing routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result includes: Obtaining routing origin authorization data of the real-time gateway data and the number of routing origin authorization data corresponding to the routing origin authorization data; When there are multiple routing origin authorization data, performing attribution association detection on the multiple routing origin authorization data to obtain the routing anomaly detection result; When the number of the routing origin authorization data is one, a routing origin authorization change detection is performed on the routing origin authorization data to obtain the routing anomaly detection result.

5. The RPKI-based routing data anomaly detection method according to claim 4, characterized in that: The performing attribution association detection on the plurality of routing origin authorization data to obtain the routing anomaly detection result includes: Obtaining the authorization agency of each routing origin authorization data, and obtaining the agency association chain of each authorization agency; When all the authorization agencies belong to the same agency association chain, performing routing origin authorization change detection on a plurality of routing origin authorization data to obtain the routing anomaly detection result; When there are at least two authorized institutions that do not belong to the same institution association chain, a routing anomaly detection result is generated to indicate that an anomaly exists in the routing origin data.

6. The RPKI-based routing data anomaly detection method according to claim 2, characterized in that: After the routing origin data is subjected to the routing origin authorization anomaly detection again after the preset detection period, the method further includes: When the routing origin authorization data corresponding to the routing origin data cannot be detected, matching multiple code number identifiers from the routing certificate revocation list based on the target code number identifier to obtain a revocation matching result; Based on the revocation matching result, a routing anomaly detection result is generated for characterizing an anomaly in the routing origin authorization data.

7. The RPKI-based routing data anomaly detection method according to claim 1, characterized in that: The acquiring, based on the gateway prefix anomaly detection result or the routing anomaly detection result, assertion replacement data corresponding to the routing origin data, and repairing the routing origin data based on the assertion replacement data, includes: When the gateway prefix anomaly detection result or the route anomaly detection result indicates that the route origin data is abnormal, prefix data filtering is performed on the real-time gateway data to obtain filtered code number data; Obtaining the assertion replacement data corresponding to the filtering code number data from an authoritative database; The resource public key data information corresponding to the real-time gateway data in the resource public key infrastructure database is replaced based on the assertion replacement data.

8. A routing data anomaly detection device based on RPKI, characterized in that: The device comprises: The code number data acquisition module is used to obtain the routing origin data from the real-time gateway data; A resource technology analysis module, configured to perform resource public key infrastructure technology analysis on the routing origin data to obtain a resource public key infrastructure technology analysis result; A gateway anomaly detection module is configured to perform a gateway prefix hijacking detection on the routing origin data to obtain a gateway prefix anomaly detection result when the resource public key infrastructure technology analysis result indicates that the real-time gateway data does not support the resource public key infrastructure technology; a routing detection module configured to, when the resource public key infrastructure technology analysis result indicates that the real-time gateway data supports the resource public key infrastructure technology, perform routing origin authorization anomaly detection on the routing origin data to obtain a routing anomaly detection result, and perform the routing origin authorization anomaly detection on the routing origin data again after a preset detection period; A repair module is used to obtain assertion replacement data corresponding to the routing origin data based on the gateway prefix anomaly detection result or the routing anomaly detection result, and repair the routing origin data based on the assertion replacement data.

9. An electronic device, characterized in that: The invention comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the RPKI-based routing data anomaly detection method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the RPKI-based routing data anomaly detection method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method for detecting and handling abnormal route, and network equipment

    CN108881295A

  • Quality detection method and device for routing origin authorization

    CN112003822A