TR-2010005: Securing BGP through Existing Infrastructure and Contractual Chains (CCBGP)
Yuri Cantor, Nancy D. Griffeth, Bilal Khan, Ping Ji · CUNY Academic Works (City University of New York) · 2010
This paper proposes a novel approach that draws upon the existing architecture and contractual relationships and compares the approach to the main existing techniques for securing BGP against prefix hijacking.We define prefix hijacking as usurping control of IP prefixes through the manipulation of BGP routing tables resulting in a redirection of network traffic away from a correct route to a prefix, which traverses all and only the ASes in the route advertisements and abides by BGP policy finally terminating at the AS that owns that prefix route, and onto another route.We further refine our definition to not include those attacks where the attacking AS lies along the correct path but does not actually route packets as it advertises.Our novel approach, termed Contractual Chained BGP, completely eliminates prefix hijacking under certain plausible assumptions 1 and provides support for accountability in the form of forensic traceback.CCBGP applies contracts to build a transient chain of links between AS neighbors and neighbors of neighbors.Because the links are transient, each AS need only be aware of the links in its contractual sphere.Keeping the contractual sphere small limits the computational requirements of creating a chain link while the overlap of the links provides the security of a complete chain.