作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (19): 103-106. doi: 10.3969/j.issn.1000-3428.2012.19.027

• 安全技术 • 上一篇    下一篇

针对BGP路由器的DDoS攻击及防范措施

张依依,祝跃飞,高 翔   

  1. (解放军信息工程大学信息工程学院,郑州 450002)
  • 收稿日期:2011-12-30 出版日期:2012-10-05 发布日期:2012-09-29
  • 作者简介:张依依(1987-),女,硕士研究生,主研方向:网络安全;祝跃飞,教授;高 翔,博士研究生
  • 基金资助:
    国家自然科学基金资助项目(60803155)

DDoS Attack Against Router with Border Gateway Protocol and Precaution

ZHANG Yi-yi, ZHU Yue-fei, GAO Xiang   

  1. (Institute of Information Engineering, PLA Information Engineering University, Zhengzhou 450002, China)
  • Received:2011-12-30 Online:2012-10-05 Published:2012-09-29

摘要: 利用有限状态机对BGP协议进行分析,结果表明使用BGP协议通信的路由器其路由表更新机制存在安全漏洞,在此基础上,提出一种针对BGP路由器的分布式拒绝服务(DDoS)攻击方法,并根据BGP路由器的通信数据,设计实现一款测试软件RouterTest用于模拟对路由器的DDoS攻击,实验结果证明了该攻击方法的有效性,并针对该攻击提出相应的防范措施。

关键词: 路由器, BGP协议, 分布式拒绝服务攻击, 有限状态机, 路由表计算

Abstract: This paper uses Finite State Machine(FSM) to analyze Border Gateway Protocol(BGP), whose results show that the update mechanism of BGP routers has safe defects. A Distributed Denial of Service(DDoS) attack method is proposed for routers with BGP. According to the communication data of BGP routers, a test software named RouterTest is designed and implemented to simulate DDoS attacks on routers. Experimental results demonstrate the effectiveness of the attack. Corresponding precautions against the attacks are also proposed.

Key words: router, Border Gateway Protocol(BGP), Distributed Denial of Service(DDoS) attack, Finite State Machine(FSM), routing table computing

中图分类号: