Inter-domain source address verification method, device, equipment and medium based on multiple information sources

By acquiring multiple information sources to build a source address verification information database and generating priority rules, the problem of misplaced forged prefixes in inter-domain source address verification is solved, and accurate source address verification is achieved.

CN120185933BActive Publication Date: 2025-09-30北京中关村实验室
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510654731.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-09-30
Estimated Expiration
2045-05-21

AI Technical Summary

Technical Problem

The existing technology cannot obtain the source address verification-specific information of all autonomous domains between domains, resulting in the misplacement of forged prefixes and the inability to generate effective source address verification rules.

Method used

By acquiring multiple information sources of the target autonomous domain, a source address verification information database is constructed, and source address verification rules are generated based on priority policies, and whitelists and blacklists are generated to perform inter-domain source address verification operations.

Benefits of technology

It effectively blocks forged traffic, avoids the accidental discarding of legitimate traffic, and improves the accuracy and reliability of source address verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185933B_ABST
    Figure CN120185933B_ABST
Patent Text Reader

Abstract

The present application relates to the field of digital information transmission technology, and more particularly to a method, apparatus, device, and medium for inter-domain source address verification based on multiple information sources. The method comprises: obtaining at least one available information source of a target autonomous domain; constructing a source address verification information library based on the at least one available information source; and generating source address verification rules for the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform inter-domain source address verification operations using the source address verification rules. This solves the problems of the prior art, such as the inability to obtain source address verification-specific information for all inter-domain autonomous domains (ASs), the difficulty in generating source address verification rules for prefixes of such ASs, and the susceptibility to the misuse of forged prefixes of such ASs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of digital information transmission technology, and in particular to a method, device, equipment and medium for verifying an inter-domain source address based on multiple information sources. Background Art

[0002] Currently, advanced inter-domain source address verification technologies, such as SAVNET, Strict uRPF, Loose uRPF, FP-uRPF, EFP-uRPF, and BAR-SAV, all use a single information source to generate source address verification rules.

[0003] Different information sources have varying degrees of authority, varying degrees of timeliness in updating when network topology or routing changes occur, and varying degrees of accuracy in source address verification rules generated from different information sources. Compared to other information sources, dedicated source address verification information is more authoritative, timely, and accurate.

[0004] However, the existing inter-domain source address verification technology based on a single information source, source address verification dedicated information, is difficult to obtain the source address verification dedicated information of all inter-domain ASs (Autonomous Systems) during the incremental deployment or partial deployment phase of the source address verification dedicated information, and is unable to generate source address verification rules for the prefixes of such ASs, resulting in the misplacement of forged prefixes of such ASs, which urgently needs to be solved. Summary of the Invention

[0005] The present application provides a method, apparatus, device and medium for inter-domain source address verification based on multiple information sources to solve the problems that the prior art cannot obtain the dedicated source address verification information of all autonomous domains AS between domains, is difficult to generate source address verification rules for the prefixes of such ASs, and is easy to mistakenly place forged prefixes of such ASs.

[0006] The first aspect of the present application provides an inter-domain source address verification method based on multiple information sources, including the following steps: obtaining at least one available information source of the target autonomous domain; constructing a source address verification information library based on the at least one available information source; generating source address verification rules of the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform inter-domain source address verification operations through the source address verification rules.

[0007] Optionally, in one embodiment of the present application, constructing the source address verification information database based on the at least one available information source includes: obtaining the source address verification information of each available information source in the at least one available information source; and constructing the source address verification information database based on the source address verification information of each available information source.

[0008] Optionally, in one embodiment of the present application, the source address verification rules of the target autonomous domain are generated based on the source address verification information base and the preset priority policy, including: using the preset priority policy to determine the target available information source with the highest priority in the source address verification information base; and generating the source address verification rules of the target autonomous domain through the target available information source.

[0009] Optionally, in one embodiment of the present application, after generating the source address verification rules of the target autonomous domain based on the source address verification information library and the preset priority policy, it also includes: generating a whitelist of the customer side interface at the customer side interface of the target autonomous domain; generating a blacklist of the peer side interface or the provider side interface at the peer side interface or the provider side interface of the target autonomous domain; determining a first target prefix that passes through the target autonomous domain from the customer side interface based on the whitelist; determining a second target prefix that will not pass through the target autonomous domain from the peer side interface or the provider side interface based on the blacklist; and excluding forged prefixes of the target autonomous domain through the first target prefix and the second target prefix.

[0010] Optionally, in one embodiment of the present application, the at least one available information source includes at least one of source address verification dedicated information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0011] The second aspect embodiment of the present application provides an inter-domain source address verification device based on multiple information sources, including: an acquisition module for acquiring at least one available information source of the target autonomous domain; a construction module for constructing a source address verification information library based on the at least one available information source; a first generation module for generating source address verification rules of the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform inter-domain source address verification operations through the source address verification rules.

[0012] Optionally, in one embodiment of the present application, the construction module includes: a collection unit for obtaining source address verification information of each available information source in the at least one available information source; and a construction unit for constructing the source address verification information database based on the source address verification information of each available information source.

[0013] Optionally, in one embodiment of the present application, the generation module includes: a first determination unit, used to use the preset priority strategy to determine the target available information source with the highest priority in the source address verification information library; a second determination unit, used to generate the source address verification rules of the target autonomous domain through the target available information source.

[0014] Optionally, in one embodiment of the present application, it also includes: a second generation module, used to generate a whitelist of the customer side interface at the customer side interface of the target autonomous domain after generating the source address verification rules of the target autonomous domain based on the source address verification information library and the preset priority policy; a third generation module, used to generate a blacklist of the peer side interface or the provider side interface at the peer side interface or the provider side interface of the target autonomous domain; a first prefix determination module, used to determine the first target prefix that passes through the target autonomous domain from the customer side interface according to the whitelist; a second prefix determination module, used to determine the second target prefix that will not pass through the target autonomous domain from the peer side interface or the provider side interface based on the blacklist; an exclusion module, used to exclude forged prefixes of the target autonomous domain through the first target prefix and the second target prefix.

[0015] Optionally, in one embodiment of the present application, the at least one available information source includes at least one of source address verification dedicated information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0016] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the program to implement the inter-domain source address verification method based on multiple information sources as described in the above embodiment.

[0017] The fourth aspect of the present application provides a computer-readable storage medium, which stores a computer program. When the program is executed by a processor, it implements the above-mentioned inter-domain source address verification method based on multiple information sources.

[0018] Therefore, the embodiments of the present application have the following beneficial effects:

[0019] The embodiments of the present application can obtain at least one available information source of the target autonomous domain; construct a source address verification information library based on the at least one available information source; generate source address verification rules for the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform inter-domain source address verification operations through the source address verification rules. The present application generates source address verification rules through the information source with the highest priority among all the available information sources of the AS, and generates a whitelist on its Customer side interface and a blacklist on its Peer or Provider side interface, thereby avoiding the accidental discarding of legitimate traffic and effectively blocking source address forged traffic. Thus, the problems that the prior art cannot obtain the source address verification-specific information of all autonomous domain ASs between domains, it is difficult to generate source address verification rules for the prefixes of this type of AS, and it is easy to mistakenly place forged prefixes of this type of AS are solved.

[0020] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0022] Figure 1 A flowchart of a method for verifying an inter-domain source address based on multiple information sources according to an embodiment of the present application is provided;

[0023] Figure 2 An example diagram of an inter-domain autonomous domain topology provided for one embodiment of the present application;

[0024] Figure 3 This is an example diagram of an inter-domain source address verification device based on multiple information sources according to an embodiment of the present application;

[0025] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0026] Among them, 10-inter-domain source address verification device based on multiple information sources, 100-acquisition module, 200-construction module, 300-first generation module, 401-memory, 402-processor, 403-communication interface. DETAILED DESCRIPTION

[0027] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0028] The following describes the inter-domain source address verification method, apparatus, device and medium based on multiple information sources of the embodiment of the present application with reference to the accompanying drawings. In response to the problems mentioned in the above background technology, the present application provides an inter-domain source address verification method based on multiple information sources. In this method, at least one available information source of the target autonomous domain is obtained; a source address verification information library is constructed based on at least one available information source; based on the source address verification information library and a preset priority policy, a source address verification rule of the target autonomous domain is generated to perform the inter-domain source address verification operation through the source address verification rule. The present application generates source address verification rules through the information source with the highest priority among all the available information sources of the AS, and generates a whitelist on its Customer side interface and a blacklist on its Peer or Provider side interface, thereby avoiding the mistaken discarding of legitimate traffic and effectively blocking source address forged traffic. Thus, the problems that the prior art cannot obtain the source address verification-specific information of all autonomous domains AS in the inter-domain, it is difficult to generate source address verification rules for the prefixes of such AS, and it is easy to mistakenly discard the prefixes of forged AS.

[0029] Specifically, Figure 1 A flowchart of a method for verifying an inter-domain source address based on multiple information sources provided in an embodiment of the present application.

[0030] like Figure 1 As shown, the inter-domain source address verification method based on multiple information sources includes the following steps:

[0031] In step S101, at least one available information source of a target autonomous domain is obtained.

[0032] The embodiments of the present application can first obtain all available information sources of the current autonomous domain (i.e., the target autonomous domain) where the inter-domain source address verification technology has been deployed, thereby providing reliable data support for generating source address verification rules for prefixes of other autonomous domains where the inter-domain source address verification technology has been deployed.

[0033] Optionally, in one embodiment of the present application, the at least one available information source includes at least one of source address verification dedicated information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0034] It should be noted that, in the embodiments of the present application, the available information sources of the above-mentioned target autonomous domain mainly include source address verification dedicated information, routing information, RPKI (Resource Public Key Infrastructure) ROA (Route Origin Authorization) data, RPKI ASPA (Autonomous System Provider Authorization) data and at least one of IRR (Internet Routing Registry) data.

[0035] Therefore, the embodiments of the present application generate inter-domain source address verification rules by obtaining multiple information sources of the target autonomous domain, and can deploy or incrementally deploy nodes in the source address verification dedicated information part, effectively improving the accuracy of source address verification.

[0036] In step S102, a source address verification information database is constructed based on at least one available information source.

[0037] After obtaining all available information sources of the target autonomous domain, the embodiments of the present application can further construct a data structure for storing source address verification information of different information sources, namely, a source address verification information database, thereby further ensuring the efficiency of source address verification rule generation through the source address verification information database.

[0038] Optionally, in one embodiment of the present application, a source address verification information database is constructed based on at least one available information source, including: obtaining source address verification information of each available information source in at least one available information source; and constructing a source address verification information database based on the source address verification information of each available information source.

[0039] During the actual implementation process, the embodiments of the present application can obtain source address verification information such as the index, prefix, prefix input direction, business relationship and source address verification information source of each available information source, and construct a source address verification information database based on the source address verification information to store the source address verification information of different information sources.

[0040] In step S103, based on the source address verification information base and the preset priority policy, a source address verification rule of the target autonomous domain is generated, so as to perform an inter-domain source address verification operation through the source address verification rule.

[0041] Furthermore, when the dedicated source address verification information of certain autonomous domains cannot be obtained, the embodiments of the present application can select the information source with the highest priority from all available information sources based on multiple information sources and the source address verification information library, and generate source address verification rules to perform inter-domain source address verification operations through the source address verification rules, thereby avoiding the accidental discarding of legitimate traffic while effectively blocking source address forged traffic.

[0042] Optionally, in one embodiment of the present application, source address verification rules for the target autonomous domain are generated based on the source address verification information library and a preset priority policy, including: using the preset priority policy to determine the target available information source with the highest priority in the source address verification information library; and generating source address verification rules for the target autonomous domain through the target available information source.

[0043] It should be noted that the embodiments of the present application can be based on multiple information sources such as source address verification dedicated information, routing information, etc. During the partial deployment or incremental deployment stage of source address verification dedicated information, the information source with the highest priority among all information sources can be obtained according to the priority ranking of various information sources as shown in Table 1.

[0044] Table 1

[0045]

[0046] As can be seen from Table 1, in the embodiment of the present application, the priority of the source address verification dedicated information is the highest, and the priority of other information sources decreases in the order of RPKI ROA and RPKI ASPA data, routing information table, forwarding information table and IRR data. Therefore, the embodiment of the present application can generate source address verification rules by obtaining the information source with the highest priority (that is, the target available information source).

[0047] Therefore, the embodiments of the present application generate source address verification rules by obtaining the information source with the highest priority among all available information sources in the target autonomous domain, thereby effectively reducing the mistaken passage of source address forged traffic while avoiding the mistaken blocking of legitimate traffic, and the embodiments of the present application can generate direct benefits once deployed.

[0048] Optionally, in one embodiment of the present application, after generating the source address verification rules of the target autonomous domain based on the source address verification information library and the preset priority policy, it also includes: generating a white list of the customer side interface at the customer side interface of the target autonomous domain; generating a black list of the peer side interface or the provider side interface at the peer side interface or the provider side interface of the target autonomous domain; determining a first target prefix that passes through the target autonomous domain from the customer side interface based on the white list; determining a second target prefix that will not pass through the target autonomous domain from the peer side interface or the provider side interface based on the black list; and excluding forged prefixes of the forged target autonomous domain through the first target prefix and the second target prefix.

[0049] As a feasible method, after generating the source address verification rules of the target autonomous domain, the embodiment of the present application can generate a whitelist of this type of interface at the Customer interface of the target autonomous domain, thereby allowing only specific prefixes (i.e., the first target prefix) to pass through the current target autonomous domain; in addition, a blacklist can be generated through the Provider or Peer interface of the target autonomous domain, etc., which are suitable for using looser source address verification rules, to discard prefixes (i.e., the second target prefix) that are determined not to pass through this autonomous domain from this type of interface, and then exclude the forged prefixes of the forged target autonomous domain through the first target prefix and the second target prefix, thereby avoiding the prefixes of the forged target autonomous domain from being mistakenly passed, and effectively blocking the source address forged traffic.

[0050] Figure 2 This application is based on the example diagram of the inter-domain autonomous domain topology. Figure 2 Taking the inter-domain autonomous domain topology shown as an example, the specific execution logic of the inter-domain source address verification method based on multiple information sources of the present application is further explained.

[0051] like Figure 2 As shown, AS 4 has four AS-level interfaces, each of which is connected to a different autonomous domain. Specifically, interface 1 is connected to AS 3, interface 2 is connected to AS 2, interface 3 is connected to AS 1, and interface 4 is connected to AS 5. Figure 2 The business relationships between the autonomous domains are: AS 3 is the provider of AS 4 and AS 5, AS 4 is the provider of AS 1, AS 2, and AS 5, and AS 2 is the provider of AS 1. Assume that prefixes P1, P2, P3, P4, P5, and P6 are all prefixes in the network. For example, the row with index 0 indicates that the valid inbound direction of prefix P1 is AS 2, and AS 2 is the customer AS of AS 4. That is, this information comes from the source address verification dedicated information.

[0052] It is understood by those skilled in the art that the source address verification information library stores source address verification related information from all information sources. The present application generates source address verification rules based on the source address verification information and its priority in the source address verification information library. At the same time, a blacklist is generated at the Provider or Peer interface of the autonomous domain, which is suitable for using looser source address verification rules, to discard prefixes that are determined not to pass through this autonomous domain from such interfaces; and a whitelist is generated at the Customer interface of the autonomous domain, which only allows specific prefixes to pass through this autonomous domain.

[0053] In addition, Table 2 is a schematic diagram of the source address verification information base of AS 4 in the inter-domain AS topology. This application uses the source address verification information base in Table 2 as an example to illustrate the logical process of generating a source address verification table and performing source address verification on the data plane.

[0054] Table 2

[0055]

[0056] Specifically, as shown in Table 2, the source address verification rules generated by AS 4 on its corresponding interfaces are as follows: the source address verification rule on interface Itf.1 is generated based on the row information indexed 0, 2, and 6 in the source address verification information base, and blocks traffic with prefixes P1, P2, and P6 from passing through AS 4 on Itf.1; the source address verification rule on interface Itf.2 is generated based on the row information indexed 0, 2, and 6 in the source address verification information base, and only allows traffic with prefixes P1 and P2 to pass through AS 4 on Itf.2; the source address verification rule on interface Itf.3 is generated based on the row information indexed 0, 1, 6, and 7 in the source address verification information base, and does not allow traffic with any prefix to pass through AS 4 on Itf.3; the source address verification rule on interface Itf.4 is generated based on the row information indexed 5 in the source address verification information base, and only allows traffic with prefix P5 to pass through AS 4, thereby avoiding the accidental discard of legitimate traffic while effectively blocking traffic with forged source addresses.

[0057] According to the inter-domain source address verification method based on multiple information sources proposed in the embodiment of the present application, at least one available information source of the target autonomous domain is obtained; a source address verification information library is constructed based on the at least one available information source; based on the source address verification information library and the preset priority strategy, the source address verification rules of the target autonomous domain are generated to perform the inter-domain source address verification operation through the source address verification rules. The present application generates source address verification rules through the information source with the highest priority among all the available information sources of the AS, and generates a whitelist on its Customer side interface and a blacklist on its Peer or Provider side interface, thereby avoiding the accidental discarding of legitimate traffic and effectively blocking source address forged traffic.

[0058] Secondly, the inter-domain source address verification device based on multiple information sources proposed in accordance with an embodiment of the present application is described with reference to the accompanying drawings.

[0059] Figure 3 It is a block diagram of an inter-domain source address verification device based on multiple information sources according to an embodiment of the present application.

[0060] like Figure 3 As shown, the inter-domain source address verification device 10 based on multiple information sources includes: an acquisition module 100 , a construction module 200 and a first generation module 300 .

[0061] The acquisition module 100 is configured to acquire at least one available information source of the target autonomous domain.

[0062] The construction module 200 is configured to construct a source address verification information database based on at least one available information source.

[0063] The first generating module 300 is configured to generate a source address verification rule of a target autonomous domain based on a source address verification information base and a preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule.

[0064] Optionally, in one embodiment of the present application, the construction module 200 includes: a collection unit and a creation unit.

[0065] The collecting unit is configured to obtain source address verification information of each available information source in at least one available information source.

[0066] An establishing unit is used to construct a source address verification information database based on the source address verification information of each available information source.

[0067] Optionally, in one embodiment of the present application, the generation module 300 includes: a first determination unit and a second determination unit.

[0068] The first determining unit is configured to determine the target available information source with the highest priority in the source address verification information database by using a preset priority strategy.

[0069] The second determining unit is configured to generate a source address verification rule of a target autonomous domain through a target available information source.

[0070] Optionally, in one embodiment of the present application, the inter-domain source address verification device 10 based on multiple information sources of the embodiment of the present application further includes: a second generation module, a third generation module, a first prefix determination module, a second prefix determination module and an exclusion module.

[0071] Among them, the second generation module is used to generate a whitelist of the Customer side interface at the Customer side interface of the target autonomous domain after generating the source address verification rules of the target autonomous domain based on the source address verification information library and the preset priority policy.

[0072] The third generating module is used to generate a blacklist of the peer side interface or the provider side interface on the peer side interface or the provider side interface of the target autonomous domain.

[0073] The first prefix determination module is configured to determine a first target prefix passing through the target autonomous domain from the customer side interface according to the whitelist.

[0074] The second prefix determination module is configured to determine, based on the blacklist, a second target prefix that will not pass through the target autonomous domain from the peer-side interface or the provider-side interface.

[0075] The exclusion module is used to exclude the forged prefix of the forged target autonomous domain through the first target prefix and the second target prefix.

[0076] Optionally, in one embodiment of the present application, the at least one available information source includes at least one of source address verification dedicated information, routing information, RPKI ROA data, RPKI ASPA data, and IRR data.

[0077] It should be noted that the aforementioned explanation of the embodiment of the inter-domain source address verification method based on multiple information sources is also applicable to the inter-domain source address verification device based on multiple information sources in this embodiment, and will not be repeated here.

[0078] According to the embodiment of the present application, the inter-domain source address verification device based on multiple information sources includes an acquisition module 100 for acquiring at least one available information source of the target autonomous domain; a construction module 200 for constructing a source address verification information library based on at least one available information source; and a first generation module 300 for generating source address verification rules of the target autonomous domain based on the source address verification information library and a preset priority policy, so as to perform inter-domain source address verification operations through the source address verification rules. The present application generates source address verification rules through the information source with the highest priority among all the available information sources of the AS, and generates a whitelist on its Customer side interface and a blacklist on its Peer or Provider side interface, thereby avoiding the accidental discarding of legitimate traffic and effectively blocking source address forged traffic.

[0079] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include:

[0080] Memory 401 , processor 402 , and computer programs stored in the memory 401 and executable on the processor 402 .

[0081] When the processor 402 executes the program, the inter-domain source address verification method based on multiple information sources provided in the above embodiment is implemented.

[0082] Furthermore, the electronic device further includes:

[0083] The communication interface 403 is used for communication between the memory 401 and the processor 402 .

[0084] The memory 401 is used to store computer programs that can be run on the processor 402 .

[0085] The memory 401 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.

[0086] If the memory 401, processor 402, and communication interface 403 are implemented independently, the communication interface 403, memory 401, and processor 402 can be connected to each other via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0087] Optionally, in a specific implementation, if the memory 401 , the processor 402 and the communication interface 403 are integrated on a chip, the memory 401 , the processor 402 and the communication interface 403 can communicate with each other through an internal interface.

[0088] The processor 402 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0089] An embodiment of the present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-mentioned inter-domain source address verification method based on multiple information sources.

[0090] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification and features of different embodiments or examples without contradiction.

[0091] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Thus, a feature specified as "first" or "second" may explicitly or implicitly include at least one such feature. In the description of this application, "N" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0092] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or N executable instructions for implementing a custom logical function or process step, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may be performed in a different order than shown or discussed, including performing functions in a substantially simultaneous manner or in a reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present application pertain.

[0093] The logic and / or steps represented in a flowchart or otherwise described herein, for example, can be considered a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" is any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (not exhaustive) of computer-readable media include: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program can be obtained electronically by optically scanning the paper or other medium and then editing, interpreting or processing it in other suitable ways as necessary, and then storing it in a computer memory.

[0094] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiment, the N steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented using hardware, as in another embodiment, any of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having logic gate circuits for implementing logical functions on data signals, an application-specific integrated circuit having suitable combinational logic gate circuits, a programmable gate array (PGA), a field-programmable gate array (FPGA), etc.

[0095] Those skilled in the art will understand that all or part of the steps in the method of the above embodiment can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0096] In addition, the functional units in the various embodiments of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into a module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0097] The storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present application. Persons skilled in the art may make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.

Claims

1. A method for verifying an inter-domain source address based on multiple information sources, characterized in that: The following steps are involved: Obtaining at least one available information source of the target autonomous domain; Building a source address verification information database based on the at least one available information source; The constructing of the source address verification information database according to the at least one available information source comprises: obtaining source address verification information of each available information source in the at least one available information source; constructing the source address verification information database based on the source address verification information of each available information source; wherein the at least one available information source comprises at least one of source address verification-specific information, routing information, RPKIROA data, RPKIASPA data, and IRR data; generating a source address verification rule for the target autonomous domain based on the source address verification information base and a preset priority policy, so as to perform an inter-domain source address verification operation according to the source address verification rule; The generating of the source address verification rule of the target autonomous domain based on the source address verification information database and the preset priority policy includes: Determine the target available information source with the highest priority in the source address verification information database by using the preset priority strategy; generating a source address verification rule of the target autonomous domain through the target available information source; After generating the source address verification rule of the target autonomous domain based on the source address verification information database and the preset priority policy, the method further includes: Generating a whitelist of the customer-side interface at the customer-side interface of the target autonomous domain; generating a blacklist of the peer-side interface or the provider-side interface on the peer-side interface or the provider-side interface of the target autonomous domain; Determine, according to the whitelist, a first target prefix passing through the target autonomous domain from the customer-side interface; Determining, based on the blacklist, a second target prefix that will not pass through the target autonomous domain from the peer-side interface or the provider-side interface; By using the first target prefix and the second target prefix, forged prefixes that forge the target autonomous domain are excluded.

2. An inter-domain source address verification device based on multiple information sources, characterized in that: include: an acquisition module, configured to acquire at least one available information source of a target autonomous domain; A construction module, configured to construct a source address verification information database based on the at least one available information source; The construction module includes: a collection unit for acquiring source address verification information of each available information source in the at least one available information source; a building unit for building the source address verification information database based on the source address verification information of each available information source; wherein the at least one available information source includes at least one of source address verification-specific information, routing information, RPKIROA data, RPKIASPA data, and IRR data; A first generating module is configured to generate a source address verification rule of the target autonomous domain based on the source address verification information base and a preset priority policy, so as to perform an inter-domain source address verification operation through the source address verification rule; Wherein, the generation module includes: A first determining unit is configured to determine a target available information source with the highest priority in the source address verification information database by using the preset priority strategy; a second determining unit, configured to generate a source address verification rule of the target autonomous domain through the target available information source; The inter-domain source address verification device based on multiple information sources also includes: A second generating module is configured to generate a whitelist of the customer-side interface at the customer-side interface of the target autonomous domain after generating a source address verification rule of the target autonomous domain based on the source address verification information library and the preset priority policy; A third generating module is configured to generate a blacklist of the peer side interface or the provider side interface in the target autonomous domain; A first prefix determination module, configured to determine a first target prefix passing through the target autonomous domain from the customer-side interface according to the whitelist; A second prefix determination module is configured to determine, based on the blacklist, a second target prefix that will not pass through the target autonomous domain from the peer-side interface or the provider-side interface; An exclusion module is configured to exclude forged prefixes that forge the target autonomous domain through the first target prefix and the second target prefix.

3. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method for inter-domain source address verification based on multiple information sources as claimed in claim 1.

4. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the inter-domain source address verification method based on multiple information sources as claimed in claim 1.

Citation Information

Patent Citations

  • Method, device and equipment for quickly verifying and tracing IPv6 address and medium

    CN114172731A

  • Verification information sending method, verification table item obtaining method, device and equipment

    CN118802247A

  • Route configuration method and device, equipment, storage medium and product

    CN119109866A