Pretty Good BGP: Improving BGP by Cautiously Adopting Routes
- 1 November 2006
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- p. 290-299
- https://doi.org/10.1109/icnp.2006.320179
Abstract
The Internet's interdomain routing protocol, BGP, is vulnerable to a number of damaging attacks, which often arise from operator misconfiguration. Proposed solutions with strong guarantees require a public-key infrastructure, accurate routing registries, and changes to BGP. However, BGP routers can avoid selecting and propagating these routes if they are cautious about adopting new reachability information. We describe a protocol- preserving enhancement to BGP, Pretty Good BGP (PGBGP), that slows the dissemination of bogus routes, providing network operators time to respond before problems escalate into large- scale Internet attacks. Simulation results show that realistic deployments of PGBGP could provide 99% of Autonomous Systems with 24 hours to investigate and repair bogus routes without affecting prefix reachability. We also show that without PGBGP, 40% of ASs cannot avoid selecting bogus routes; with PGBGP, this number drops to less than 1%. Finally, we show that PGBGP is incrementally deployable and offers significant security benefits to early adopters and their customers.Keywords
This publication has 12 references indexed in Scilit:
- BPG routing policies in ISP networksIEEE Network, 2005
- The case for separating routing from routersPublished by Association for Computing Machinery (ACM) ,2004
- Protecting BGP routes to top-level DNS serversIEEE Transactions on Parallel and Distributed Systems, 2003
- Detection of invalid routing announcement in the InternetPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Topology-Based Detection of Anomalous BGP MessagesLecture Notes in Computer Science, 2003
- Securing the border gateway routing protocolPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Understanding BGP misconfigurationPublished by Association for Computing Machinery (ACM) ,2002
- BGP routing stability of popular destinationsPublished by Association for Computing Machinery (ACM) ,2002
- Stable Internet routing without global coordinationIEEE/ACM Transactions on Networking, 2001
- Secure Border Gateway Protocol (S-BGP)IEEE Journal on Selected Areas in Communications, 2000