Inter-domain source address verification method and device based on multiple information sources, equipment and medium

By obtaining multiple information sources to build a source address verification information database and generating the highest priority source address verification rules, the problem that the existing technology cannot obtain source address verification dedicated information for all autonomous domain ASs between domains is solved, and effective source address verification and forged traffic blocking are achieved.

CN120185933AActive Publication Date: 2025-06-20北京中关村实验室
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510654731.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-06-20
Estimated Expiration
2045-05-21

AI Technical Summary

Technical Problem

The prior art cannot obtain source address verification information for all autonomous domain ASs between domains, and it is difficult to generate source address verification rules for the prefixes of this type of ASs, and it is easy to mistakenly place prefixes of this type of ASs.

Method used

By obtaining at least one available information source of the target autonomous domain, a source address verification information database is constructed, and based on the information database and the preset priority policy, a source address verification rule for the target autonomous domain is generated to perform the inter-domain source address verification operation.

Benefits of technology

By using multiple information sources to generate source address verification rules, it can effectively avoid accidentally discarding legitimate traffic and blocking source address forgery traffic, solving the problem that the source address verification dedicated information of all ASs cannot be obtained in the prior art.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185933A_ABST
    Figure CN120185933A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of digital information transmission, in particular to an inter-domain source address verification method and device based on multiple information sources, equipment and a medium, and the method comprises the steps: obtaining at least one available information source of a target autonomous domain; constructing a source address verification information base according to the at least one available information source; and generating a source address verification rule of the target autonomous domain based on the source address verification information base and a preset priority strategy, so as to execute an inter-domain source address verification operation through the source address verification rule. Therefore, the problems that in the prior art, source address verification special information of all autonomous domains AS among the domains cannot be obtained, source address verification rules are difficult to generate for prefixes of the AS, and the prefixes of the AS are prone to being misplaced and forged are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of digital information transmission technology, and particularly relates to an inter-domain source address verification method, device, equipment and medium based on multiple information sources. Background Art

[0002] Currently, advanced inter-domain source address verification technologies, such as SAVNET, Strict uRPF, Loose uRPF, FP-uRPF, EFP-uRPF, BAR-SAV, etc., all use a single information source to generate source address verification rules.

[0003] The authorities of different information sources are different, their timeliness of update is different when the network topology or routing changes, and the accuracy of source address verification rules generated based on different information sources is also different. Compared with other information sources, the dedicated information for source address verification is more authoritative, timely and accurate.

[0004] However, in the existing inter-domain source address verification technology based on a single information source of dedicated information for source address verification, it is difficult to obtain the dedicated information for source address verification of all autonomous systems (ASs) in the inter-domain during the incremental deployment or partial deployment stage of the dedicated information for source address verification, and it is impossible to generate source address verification rules for the prefixes of such ASs, resulting in the forged prefixes of such ASs being misclassified, which urgently needs to be solved. Summary of the Invention

[0005] This application provides an inter-domain source address verification method, device, equipment and medium based on multiple information sources to solve the problems in the prior art that it is impossible to obtain the dedicated information for source address verification of all autonomous systems (ASs) in the inter-domain, it is difficult to generate source address verification rules for the prefixes of such ASs, and it is easy to misclassify the forged prefixes of such ASs.

[0006] The first aspect of the embodiments of this application provides an inter-domain source address verification method based on multiple information sources, including the following steps: obtaining at least one available information source of a target autonomous system; constructing a source address verification information library according to the at least one available information source; generating a source address verification rule of the target autonomous system based on the source address verification information library and a preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule.

[0007] Optionally, in an embodiment of this application, the constructing a source address verification information library according to the at least one available information source includes: obtaining the source address verification information of each available information source in the at least one available information source; constructing the source address verification information library based on the source address verification information of each available information source.

[0008] Optionally, in an embodiment of the present application, generating the source address verification rule of the target autonomous domain based on the source address verification information library and the preset priority policy includes: determining the target available information source with the highest priority in the source address verification information library by using the preset priority policy; generating the source address verification rule of the target autonomous domain through the target available information source.

[0009] Optionally, in an embodiment of the present application, after generating the source address verification rule of the target autonomous domain based on the source address verification information library and the preset priority policy, it further includes: generating a whitelist of the Customer-side interface in the Customer-side interface of the target autonomous domain; generating a blacklist of the Peer-side interface or the Provider-side interface in the Peer-side interface or the Provider-side interface of the target autonomous domain; determining a first target prefix passing through the target autonomous domain from the Customer-side interface according to the whitelist; determining a second target prefix that will not pass through the target autonomous domain from the Peer-side interface or the Provider-side interface based on the blacklist; excluding the forged prefix forging the target autonomous domain through the first target prefix and the second target prefix.

[0010] Optionally, in an embodiment of the present application, the at least one available information source includes at least one of source address verification dedicated information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0011] An embodiment of the second aspect of the present application provides an inter-domain source address verification device based on multiple information sources, including: an acquisition module, configured to acquire at least one available information source of a target autonomous domain; a construction module, configured to construct a source address verification information library according to the at least one available information source; a first generation module, configured to generate a source address verification rule of the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule.

[0012] Optionally, in an embodiment of the present application, the construction module includes: a collection unit, configured to acquire the source address verification information of each available information source in the at least one available information source; an establishment unit, configured to construct the source address verification information library based on the source address verification information of each available information source.

[0013] Optionally, in an embodiment of the present application, the generating module includes: a first determining unit, configured to determine, by using the preset priority policy, a target available information source with the highest priority in the source address verification information library; a second determining unit, configured to generate, by using the target available information source, a source address verification rule for the target autonomous domain.

[0014] Optionally, in an embodiment of the present application, it further includes: a second generating module, configured to generate a whitelist for the Customer side interface at the Customer side interface of the target autonomous domain after generating the source address verification rule for the target autonomous domain based on the source address verification information library and the preset priority policy; a third generating module, configured to generate a blacklist for the Peer side interface or the Provider side interface at the Peer side interface or the Provider side interface of the target autonomous domain; a first prefix determining module, configured to determine, according to the whitelist, a first target prefix passing through the target autonomous domain from the Customer side interface; a second prefix determining module, configured to determine, based on the blacklist, a second target prefix that will not pass through the target autonomous domain from the Peer side interface or the Provider side interface; an excluding module, configured to exclude a forged prefix forging the target autonomous domain by using the first target prefix and the second target prefix.

[0015] Optionally, in an embodiment of the present application, the at least one available information source includes at least one of source address verification dedicated information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0016] An embodiment of the third aspect of the present application provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the processor executes the program to implement the multi-information-source-based inter-domain source address verification method as described in the above embodiment.

[0017] An embodiment of the fourth aspect of the present application provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and when the program is executed by a processor, it implements the above multi-information-source-based inter-domain source address verification method.

[0018] Therefore, the embodiments of the present application have the following beneficial effects: Embodiments of the present application can obtain at least one available information source of a target autonomous domain; construct a source address verification information library according to the at least one available information source; generate a source address verification rule for the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule. The present application generates a source address verification rule through the information source with the highest priority among all available information sources of the AS, generates a whitelist at its Customer-side interface, and generates a blacklist at its Peer or Provider-side interface, thereby avoiding mis-discarding legitimate traffic and effectively blocking source address forged traffic. Thus, the problems in the prior art that it is impossible to obtain dedicated information for source address verification of all autonomous domains (ASs) between domains, it is difficult to generate source address verification rules for prefixes of such ASs, and it is easy to misplace prefixes forged for such ASs are solved.

[0019] Additional aspects and advantages of the present application will be given in part in the following description, become apparent in part from the following description, or be understood through the practice of the present application. Brief Description of the Drawings

[0020] The above and / or additional aspects and advantages of the present application will become apparent and be readily understood from the following description of the embodiments in conjunction with the drawings, in which: Figure 1 is a flowchart of a method for inter-domain source address verification based on multiple information sources according to an embodiment of the present application; Figure 2 is an example diagram of an inter-domain autonomous domain topology provided by an embodiment of the present application; Figure 3 is an example diagram of an inter-domain source address verification device based on multiple information sources according to an embodiment of the present application; Figure 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application.

[0021] Wherein, 10 - inter-domain source address verification device based on multiple information sources, 100 - acquisition module, 200 - construction module, 300 - first generation module, 401 - memory, 402 - processor, 403 - communication interface. Detailed Description of the Embodiments

[0022] The embodiments of the present application will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements with the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present application and should not be construed as limiting the present application.

[0023] The method, apparatus, device, and medium for inter-domain source address verification based on multiple information sources according to the embodiments of the present application will be described below with reference to the accompanying drawings. To address the problems mentioned in the above background art, the present application provides a method for inter-domain source address verification based on multiple information sources. In this method, at least one available information source of the target autonomous system (AS) is obtained; a source address verification information library is constructed based on the at least one available information source; and a source address verification rule for the target AS is generated based on the source address verification information library and a preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule. The present application generates a source address verification rule through the information source with the highest priority among all available information sources of the AS, generates a whitelist at its Customer-side interface, and generates a blacklist at its Peer or Provider-side interface, thereby avoiding mis-discarding legitimate traffic and effectively blocking source address forged traffic. Thus, the problems in the prior art that it is impossible to obtain the dedicated information for source address verification of all autonomous systems (ASs) between domains, it is difficult to generate a source address verification rule for the prefixes of such ASs, and it is easy to mis-release the prefixes forged for such ASs are solved.

[0024] Specifically, Figure 1 FIG. is a flowchart of a method for inter-domain source address verification based on multiple information sources provided by an embodiment of the present application.

[0025] As Figure 1 shown, the method for inter-domain source address verification based on multiple information sources includes the following steps: In step S101, at least one available information source of the target AS is obtained.

[0026] First, the embodiments of the present application can obtain all available information sources of the current AS (i.e., the target AS) where the inter-domain source address verification technology has been deployed, so as to provide reliable data support for generating source address verification rules for the prefixes of other ASs where the inter-domain source address verification technology has been deployed.

[0027] Optionally, in an embodiment of the present application, the at least one available information source includes at least one of dedicated information for source address verification, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0028] It should be noted that, in the embodiments of the present application, the available information sources of the above target autonomous domain mainly include at least one of source address verification dedicated information, routing information, RPKI (Resource Public Key Infrastructure) ROA (Route Origin Authorization) data, RPKI ASPA (Autonomous System Provider Authorization) data, and IRR (Internet Routing Registry) data.

[0029] Thus, the embodiments of the present application generate inter-domain source address verification rules by obtaining multiple information sources of the target autonomous domain, and nodes can be deployed or incrementally deployed in the source address verification dedicated information part, effectively improving the accuracy of source address verification.

[0030] In step S102, a source address verification information library is constructed according to at least one available information source.

[0031] After obtaining all available information sources of the target autonomous domain, further, the embodiments of the present application can also construct a data structure for storing source address verification information of different information sources, that is, a source address verification information library, so as to further ensure the efficiency of generating source address verification rules through the source address verification information library.

[0032] Optionally, in an embodiment of the present application, constructing a source address verification information library according to at least one available information source includes: obtaining the source address verification information of each available information source in at least one available information source; and constructing a source address verification information library based on the source address verification information of each available information source.

[0033] In the actual execution process, the embodiments of the present application can obtain source address verification information such as the index, prefix, prefix incoming direction, business relationship, and source address verification information source of each available information source, and construct a source address verification information library according to the source address verification information to store the source address verification information of different information sources.

[0034] In step S103, based on the source address verification information library and a preset priority policy, source address verification rules for the target autonomous domain are generated to perform inter-domain source address verification operations through the source address verification rules.

[0035] Furthermore, when the source address verification dedicated information of some autonomous domains cannot be obtained, the embodiments of the present application can select the information source with the highest priority from all available information sources based on multiple information sources and the source address verification information library, generate a source address verification rule, and perform an inter-domain source address verification operation through the source address verification rule, so as to effectively block the source address forged traffic while avoiding mis-discarding legitimate traffic.

[0036] Optionally, in an embodiment of the present application, generating a source address verification rule for a target autonomous domain based on the source address verification information library and a preset priority policy includes: determining the target available information source with the highest priority in the source address verification information library by using the preset priority policy; generating a source address verification rule for the target autonomous domain through the target available information source.

[0037] It should be noted that the embodiments of the present application can be based on multiple information sources such as source address verification dedicated information and routing information. During the deployment or incremental deployment phase of the source address verification dedicated information, the information source with the highest priority among all information sources can be obtained according to the priority ranking of various information sources shown in Table 1.

[0038] Table 1

[0039] As can be seen from Table 1, in the embodiments of the present application, the priority of the source address verification dedicated information is the highest, while the priorities of other information sources decrease in the order of RPKI ROA and RPKI ASPA data, routing information table, forwarding information table, and IRR data. Therefore, the embodiments of the present application can generate a source address verification rule by obtaining the information source with the highest priority (i.e., the target available information source).

[0040] Thus, the embodiments of the present application generate a source address verification rule by obtaining the information source with the highest priority among all available information sources of the target autonomous domain, so as to effectively reduce the mis-passing of source address forged traffic while avoiding mis-blocking of legitimate traffic, and the embodiments of the present application can generate direct benefits once deployed.

[0041] Optionally, in an embodiment of the present application, after generating the source address verification rule for the target autonomous domain based on the source address verification information library and the preset priority policy, the following steps are further included: generating a whitelist for the Customer-side interface of the target autonomous domain at the Customer-side interface of the target autonomous domain; generating a blacklist for the Peer-side interface or the Provider-side interface at the Peer-side interface or the Provider-side interface of the target autonomous domain; determining the first target prefix passing through the target autonomous domain from the Customer-side interface according to the whitelist; determining the second target prefix that will not pass through the target autonomous domain from the Peer-side interface or the Provider-side interface based on the blacklist; and excluding the forged prefixes forging the target autonomous domain through the first target prefix and the second target prefix.

[0042] As an implementable manner, after generating the source address verification rule for the target autonomous domain, the embodiment of the present application can generate a whitelist for this type of interface at the Customer interface of the target autonomous domain, so as to only allow specific prefixes (i.e., the first target prefix) to pass through the current target autonomous domain; in addition, a blacklist can be generated through interfaces such as the Provider or Peer of the target autonomous domain that are suitable for using a relatively loose source address verification rule, so as to discard the prefixes (i.e., the second target prefix) that are determined not to pass through this autonomous domain from this type of interface, and then exclude the forged prefixes forging the target autonomous domain through the first target prefix and the second target prefix, thereby avoiding the forged prefixes of the target autonomous domain from being accidentally passed, and effectively blocking the source address forgery traffic.

[0043] Figure 2 For the inter-domain autonomous domain topology example diagram. The present application takes Figure 2 the inter-domain autonomous domain topology shown as an example to further illustrate the specific execution logic of the inter-domain source address verification method based on multiple information sources of the present application.

[0044] As Figure 2 shown, AS 4 has four AS-level interfaces, and each interface is connected to a different autonomous domain. Specifically, interface 1 is connected to AS 3, interface 2 is connected to AS 2, interface 3 is connected to AS 1, and interface 4 is connected to AS 5. Among them, Figure 2 the business relationships between the autonomous domains are as follows: AS 3 is the Provider of AS 4 and AS 5, AS 4 is the Provider of AS 1, AS 2 and AS 5, AS 2 is the Provider of AS 1, and it is assumed that prefixes P1, P2, P3, P4, P5 and P6 are all the prefixes in the network. For example, the row with index 0 indicates that the valid incoming direction of prefix P1 is AS 2, and AS 2 is the Customer AS of AS 4, that is, this information comes from the source address verification dedicated information.

[0045] Those skilled in the art can understand that the source address verification information library stores source address verification-related information from all information sources, and this application generates source address verification rules based on the source address verification information and its priority in the source address verification information library. At the same time, blacklists are generated at interfaces such as the Provider or Peer interfaces of the autonomous domain that are suitable for using relatively loose source address verification rules to discard prefixes that are determined not to pass through this autonomous domain from such interfaces; while whitelists are generated at the Customer interfaces of the autonomous domain, and only specific prefixes are allowed to pass through this autonomous domain.

[0046] In addition, Table 2 is a schematic diagram of the source address verification information library of AS 4 in the inter-domain AS topology. This application takes the source address verification information library in Table 2 as an example to illustrate the logical process of generating the source address verification table and performing source address verification on the data plane.

[0047] Table 2

[0048] Specifically, as shown in Table 2, the source address verification rules generated by AS 4 on its corresponding interfaces are as follows: The source address verification rule on interface Itf.1 is generated based on the row information with indexes 0, 2, and 6 in the source address verification information library, blocking the traffic of prefixes P1, P2, and P6 from passing through AS 4 on Itf.1; the source address verification rule on interface Itf.2 is generated based on the row information with indexes 0, 2, and 6 in the source address verification information library, only allowing the traffic of prefixes P1 and P2 to pass through AS 4 on Itf.2; the source address verification rule on interface Itf.3 is generated based on the row information with indexes 0, 1, 6, and 7 in the source address verification information library, not allowing any prefix traffic to pass through AS 4 on Itf.3; the source address verification rule on interface Itf.4 is generated based on the row information with index 5 in the source address verification information library, only allowing the traffic of prefix P5 to pass through AS 4, thus effectively blocking source address spoofing traffic while avoiding misdiscarding legitimate traffic.

[0049] According to the inter-domain source address verification method based on multiple information sources proposed in the embodiments of this application, at least one available information source of the target autonomous domain is obtained; a source address verification information library is constructed according to the at least one available information source; and source address verification rules for the target autonomous domain are generated based on the source address verification information library and a preset priority policy to perform inter-domain source address verification operations through the source address verification rules. This application generates source address verification rules through the information source with the highest priority among all available information sources of the AS, generates a whitelist at its Customer-side interface, and generates a blacklist at its Peer or Provider-side interface, thus avoiding misdiscarding legitimate traffic and effectively blocking source address spoofing traffic.

[0050] Next, a device for inter-domain source address verification based on multiple information sources according to an embodiment of the present application will be described with reference to the accompanying drawings.

[0051] Figure 3 It is a block diagram of a device for inter-domain source address verification based on multiple information sources according to an embodiment of the present application.

[0052] As Figure 3 shown, the device 10 for inter-domain source address verification based on multiple information sources includes: an acquisition module 100, a construction module 200, and a first generation module 300.

[0053] Among them, the acquisition module 100 is configured to acquire at least one available information source of a target autonomous domain.

[0054] The construction module 200 is configured to construct a source address verification information library according to at least one available information source.

[0055] The first generation module 300 is configured to generate a source address verification rule for the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule.

[0056] Optionally, in an embodiment of the present application, the construction module 200 includes: a collection unit and an establishment unit.

[0057] Among them, the collection unit is configured to acquire source address verification information of each available information source in at least one available information source.

[0058] The establishment unit is configured to construct a source address verification information library based on the source address verification information of each available information source.

[0059] Optionally, in an embodiment of the present application, the generation module 300 includes: a first determination unit and a second determination unit.

[0060] Among them, the first determination unit is configured to determine the target available information source with the highest priority in the source address verification information library by using the preset priority policy.

[0061] The second determination unit is configured to generate a source address verification rule for the target autonomous domain through the target available information source.

[0062] Optionally, in an embodiment of the present application, the device 10 for inter-domain source address verification based on multiple information sources according to an embodiment of the present application further includes: a second generation module, a third generation module, a first prefix determination module, a second prefix determination module, and an exclusion module.

[0063] Among them, the second generation module is used to generate a whitelist for the Customer side interface of the target autonomous domain after generating the source address verification rule of the target autonomous domain based on the source address verification information library and the preset priority policy.

[0064] The third generation module is used to generate a blacklist for the Peer side interface or the Provider side interface of the target autonomous domain.

[0065] The first prefix determination module is used to determine the first target prefix passing through the target autonomous domain from the Customer side interface according to the whitelist.

[0066] The second prefix determination module is used to determine the second target prefix that will not pass through the target autonomous domain from the Peer side interface or the Provider side interface based on the blacklist.

[0067] The exclusion module is used to exclude the forged prefixes that forge the target autonomous domain through the first target prefix and the second target prefix.

[0068] Optionally, in an embodiment of the present application, at least one available information source includes at least one of source address verification dedicated information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0069] It should be noted that the foregoing explanation of the embodiment of the inter-domain source address verification method based on multiple information sources also applies to the inter-domain source address verification device based on multiple information sources in this embodiment, and will not be elaborated here.

[0070] The inter-domain source address verification device proposed according to the embodiment of the present application includes an acquisition module 100, which is used to acquire at least one available information source of the target autonomous domain; a construction module 200, which is used to construct a source address verification information library according to at least one available information source; and a first generation module 300, which is used to generate a source address verification rule of the target autonomous domain based on the source address verification information library and the preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule. The present application generates a source address verification rule through the information source with the highest priority among all available information sources of the AS, generates a whitelist for its Customer side interface, and generates a blacklist for its Peer or Provider side interface, thereby avoiding mis-discarding legitimate traffic and effectively blocking source address forged traffic.

[0071] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device may include: A memory 401, a processor 402, and a computer program stored on the memory 401 and executable on the processor 402.

[0072] When the processor 402 executes the program, it implements the method for verifying the source address between domains based on multiple information sources provided in the above embodiments.

[0073] Furthermore, the electronic device further includes: A communication interface 403 for communication between the memory 401 and the processor 402.

[0074] A memory 401 for storing a computer program that can run on the processor 402.

[0075] The memory 401 may include a high-speed RAM memory, and may also include non-volatile memory, such as at least one disk memory.

[0076] If the memory 401, the processor 402, and the communication interface 403 are implemented independently, the communication interface 403, the memory 401, and the processor 402 can be interconnected through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 4 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0077] Optionally, in a specific implementation, if the memory 401, the processor 402, and the communication interface 403 are integrated on a chip, the memory 401, the processor 402, and the communication interface 403 can communicate with each other through an internal interface.

[0078] The processor 402 may be a Central Processing Unit (CPU), or an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0079] The embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method for verifying the source address between domains based on multiple information sources as described above.

[0080] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc., mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0081] In addition, the terms "first" and "second" are used only for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of this application, the meaning of "N" is at least two, such as two, three, etc., unless otherwise specifically defined.

[0082] Any process or method description shown in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or N executable instructions for implementing a customized logic function or process, and the scope of the preferred embodiments of this application includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in the reverse order according to the involved functions, rather than in the order shown or discussed, which should be understood by those skilled in the art to which the embodiments of this application belong.

[0083] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definable sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection part (electronic device) having one or N wirings, a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then stored in a computer memory.

[0084] It should be understood that the various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, the N steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented using hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits having suitable combinational logic gate circuits, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0085] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the methods of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0086] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0087] The above-mentioned storage medium can be a read-only memory, a magnetic disk or an optical disc, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A method for verifying an inter-domain source address based on multiple information sources, characterized in that: The following steps are involved: Acquire at least one available information source of the target autonomous domain; Building a source address verification information library based on the at least one available information source; Based on the source address verification information base and the preset priority policy, a source address verification rule of the target autonomous domain is generated to perform an inter-domain source address verification operation through the source address verification rule.

2. The method for verifying inter-domain source addresses based on multiple information sources according to claim 1, characterized in that: The step of constructing a source address verification information database according to the at least one available information source comprises: Obtaining source address verification information of each available information source of the at least one available information source; The source address verification information database is constructed based on the source address verification information of each available information source.

3. The method for verifying inter-domain source addresses based on multiple information sources according to claim 1, characterized in that: The generating the source address verification rule of the target autonomous domain based on the source address verification information base and the preset priority policy includes: Determine the target available information source with the highest priority in the source address verification information base by using the preset priority strategy; A source address verification rule of the target autonomous domain is generated through the target available information source.

4. The method for verifying inter-domain source addresses based on multiple information sources according to claim 3, characterized in that: After generating the source address verification rule of the target autonomous domain based on the source address verification information base and the preset priority policy, the method further includes: Generating a whitelist of the Customer-side interface at the Customer-side interface of the target autonomous domain; Generating a blacklist of the Peer side interface or the Provider side interface at the Peer side interface or the Provider side interface of the target autonomous domain; Determine, according to the whitelist, a first target prefix passing through the target autonomous domain from the Customer side interface; Based on the blacklist, determining a second target prefix that will not pass through the target autonomous domain from the peer side interface or the provider side interface; By using the first target prefix and the second target prefix, forged prefixes that forge the target autonomous domain are excluded.

5. The method for verifying inter-domain source addresses based on multiple information sources according to claim 1, characterized in that: The at least one available information source includes at least one of source address verification specific information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

6. An inter-domain source address verification device based on multiple information sources, characterized in that: include: An acquisition module, used to acquire at least one available information source of a target autonomous domain; A construction module, configured to construct a source address verification information base according to the at least one available information source; The first generating module is used to generate the source address verification rule of the target autonomous domain based on the source address verification information base and the preset priority policy, so as to perform the inter-domain source address verification operation through the source address verification rule.

7. The device for verifying inter-domain source addresses based on multiple information sources according to claim 6, characterized in that: The building blocks include: A collection unit, configured to obtain source address verification information of each available information source in the at least one available information source; The establishing unit is used to construct the source address verification information library based on the source address verification information of each available information source.

8. The device for verifying inter-domain source addresses based on multiple information sources according to claim 6, characterized in that: The generation module comprises: A first determining unit, configured to determine a target available information source with the highest priority in the source address verification information base by using the preset priority strategy; The second determining unit is configured to generate a source address verification rule of the target autonomous domain through the target available information source.

9. The device for verifying inter-domain source addresses based on multiple information sources according to claim 8, characterized in that: Also includes: A second generating module is used to generate a whitelist of the Customer side interface at the Customer side interface of the target autonomous domain after generating the source address verification rule of the target autonomous domain based on the source address verification information base and the preset priority policy; A third generating module is used to generate a blacklist of the Peer side interface or the Provider side interface in the target autonomous domain; A first prefix determination module, configured to determine a first target prefix passing through the target autonomous domain from the Customer side interface according to the whitelist; A second prefix determination module, configured to determine, based on the blacklist, a second target prefix that will not pass through the target autonomous domain from the Peer side interface or the Provider side interface; An exclusion module is used to exclude a forged prefix that forges the target autonomous domain through the first target prefix and the second target prefix.

10. The device for verifying inter-domain source addresses based on multiple information sources according to claim 6, characterized in that: The at least one available information source includes at least one of source address verification specific information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

11. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the inter-domain source address verification method based on multiple information sources as described in any one of claims 1 to 5.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the inter-domain source address verification method based on multiple information sources as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method, device and equipment for quickly verifying and tracing IPv6 address and medium

    CN114172731A

  • Inter-domain source address anomaly detection method and device, storage medium and network equipment

    CN116055120A

  • Source address traffic identification and control method and device based on programmable data plane, equipment and medium

    CN118611955A

  • Verification information sending method, verification table item obtaining method, device and equipment

    CN118802247A

  • Method and device for acquiring source address verification table item

    CN119011167A