An Origin AS Verification Mechanism Based on the Length of Prefix Assignment Path for Securing BGP

Binqiang Wang · Dianzi xuebao · 2009

The paper found that current origin Autonomous System(AS)verification mechanisms to secure BGP which security property have been widely recognized,such as S-BGP,have the vulnerability that they are based on the assignment path of a prefix,only guarantee that a prefix is originated by the AS which is authorized by an Internet Service Provider(ISP)at the assignment path of the prefix,not guarantee that it is originated by the AS authorized by the last ISP,which owns the prefix.Only the AS authorized by the ISP owns a prefix is the prefix's legitimate origin AS.As a result,these mechanisms suffer from a 'the upper ISP' prefix hijacking.The paper proposes a novel origin AS verification mechanism based on the length of a prefix assignment path for securing BGP,called LAP(the Length of Assignment Path).The basic idea is that all ASes must provide the assignment path and attestations of their originated prefixes,and for a prefix,the AS provides the longest valid assignment path is its legitimate origin AS.LAP protect inter-domain routing system against valid prefix hijacking,sub-prefix hijacking and unused prefix hijacking,especially 'the upper ISP' prefix hijacking,and it can be seamlessly applied in current BGP secure solutions and some next generation inter-domain routing protocols.

Read the paper · More papers on PaperTik