Attack-Tree-Based Security Testing of BGP

Nian Qi-feng · Computer Engineering and Science · 2006

The inter-domain routing system based on BGP is the key routing infrastructure in the Internet. However, it is prone to imprudence errors and is menaced by many aggressive attacks. In this paper, we introduce an attack-tree model of BGP, and design a testing suite which can use the model to identify the vulnerability of the inter-domain routing system. The key part of the testing procedure is the process of marking attack-trees, and we present a coloring algorithm to solve it. The model can not only test the security of BGP comprehensively, but also facilitate the generation of testing-cases and the implementation of systems. Using the generated testing-cases, we test the security of a target BGP system and the results indicate that this method can effectively expose the vulnerabilities of BGP, which helps ISP enhance routing systems.

Read the paper · More papers on PaperTik