Vulnerability analysis, intrusion prevention and detection for link state routing protocols
Feiyi Wang, Shyhtsun Felix Wu · 2000
The objective of this dissertation is to study the vulnerabilities of link state routing protocol, design and implement new approaches for intrusion prevention and detection. As one of the cornerstones of network infrastructure, routing systems are facing more threats than ever: they are vulnerable by nature and challenging to protect. Drawing upon working results from two DARPA research projects, JiNao (Scalable Intrusion Detection for the Emerging Network Infrastructure) and GIANT (Global Intrusion Assessment Through Distributed Decision Making), the dissertation makes the following contributions: First, it systematically analyzes the vulnerabilities of link state routing protocol from design, impl-mentation, environment, and configuration aspects, making comparisons with other distance vector based protocols when necessary and discovering potential attack points. The vulnerability analysis establishes foundations for prevention and intrusion detection. Second, it describes the design and implementation of wrapper-based active protection for routing protocol, which are most suitable to prevent known vulnerabilities and provide architectural advantage to legacy systems. Third, it describes integrated network management (INM) based intrusion detection method. The integration of management and control planes will