Increasing Network Resilience to Persistent OSPF Attacks
Russell Meredith, Rudra Dutta · 2019
Routing protocols, including OSPF, are essential for correct network function and therefore attractive targets for attackers. Many attacks on OSPF are known. Limited progress on detection and prevention has meant that protecting against and recovering from such attacks typically requires significant manual effort. The goal of this research is to make networks more resilient to all known attacks that exploit OSPF Link State Advertisements (LSAs), without requiring modifications to the OSPF protocol. The proposed solution adds a Virtual Routing Resilience Cluster (VRRC) to the network infrastructure. This cluster makes use of three concepts. The first is that new links are added infrequently to networks. By comparing with previous topology information, suspect LSA information can be detected and rejected. The second is that it should be possible to corroborate LSAs by comparing with data made available from other layers of the network. LSAs that conflict with data from other layers can safely be rejected. The third is a rudimentary recovery and adaptation system designed to reestablish network connectivity and prevent the attack from happening again. This can be accomplished by purging the routing table and generating routing policies to block the offending source of the attack. We show that these concepts lead to protection against all known OSPF attacks, and that the concepts are feasible to implement, without resorting to the complexity of key management, and without modifying the routing protocol. The ability of the network to reconfigure around normal routing failures is also not compromised. A VRRC was added to a testbed consisting of standard routers, and shown to provide protection against state of the art attacks. The impact of the implementation on network throughput and router CPU usage is shown.