Secure Routing Protocols Using Consistency Checks and S-RIP
نویسندگان
چکیده
Internet routing infrastructures are vulnerable to various attacks due to the lack of strong authentication mechanisms, software vulnerabilities/misconfiguration, and the risky assumption of a trustworthy and cooperative environment. Existing solutions do not solve the problem because they neither validate factual correctness of routing updates nor support incremental deployment. In this paper, we propose a data correlation approach for validating routing information. A routing update is validated for its factual correctness before being used to update a routing table by cross checking its consistency among selected nodes which are informed of that update. The notion of trust or distrust is replaced by node reputation measured by numerical values. The tradeoff between security and efficiency is made by configurable thresholds and a sized window which determines how many nodes to involve in a consistency check. As a first example of applying the framework, we develop an incrementally deployable protocol, namely (S-RIP), for securing Routing Information Protocol (RIP). We have implemented S-RIP in the network simulator NS2. We show that with S-RIP, a nonfaulty node can uncover inconsistent routing information in a network with many misbehaving nodes given that no two of them are in collusion. Additional routing overhead generated by S-RIP is adjustable and can be reduced to a reasonalbe level.
منابع مشابه
S-RIP: A Secure Distance Vector Routing Protocol
Distance vector routing protocols (e.g., RIP) have been widely used on the Internet, and are being adapted to emerging wireless ad hoc networks. However, it is well-known that existing distance vector routing protocols are insecure due to: 1) the lack of strong authentication and authorization mechanisms; 2) the difficulty, if not impossibility, of validating routing updates which are aggregate...
متن کاملSecure Routing Protocol: Affection on MANETs Performance
In mobile ad hoc networks, the absence ofinfrastructure and the consequent absence of authorizationfacilities impede the usual practice of establishing a practicalcriterion to distinguishing nodes as trusted and distrusted.Since all nodes in the MANETs would be used as router inmulti-hop applications, secure routing protocols have vital rulein the security of the network. So evaluating the perf...
متن کاملTitle: Socrates on Ip Router Fault Detection General Conference Topics: Communications Quality & Reliability, N E T Work Operations & Management Socrates on Ip Router Fault Detection
SOCRATES is a software system for testing correctness of im plementations of IP routing protocols such as RIP OSPF and BGP It uses a probabilistic algorithm to construct random network topologies For each generated network topology it checks the correctness of routing table cal culation and the IP packet forwarding behavior For OSPF it also checks the consistency between network topologies and ...
متن کاملManaging Complexity of Designing Routing Protocols Using a Middleware Approach
Designing and architecting new routing protocols is an expensive task, because they are complex systems managing distributed network state, in order to create and maintain the routing databases. Existing routing protocol implementations are compact, bundling together a database, an optimal path calculation algorithm and a network state distribution mechanism. The aim of this paper is to present...
متن کاملSummary of Cryptographic Authentication Algorithm Implementation Requirements for Routing Protocols
The routing protocols Open Shortest Path First version 2 (OSPFv2), Intermediate System to Intermediate System (IS-IS), and Routing Information Protocol (RIP) currently define cleartext and MD5 (Message Digest 5) methods for authenticating protocol packets. Recently, effort has been made to add support for the SHA (Secure Hash Algorithm) family of hash functions for the purpose of authenticating...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2003