博碩士論文 110423012 完整後設資料紀錄

DC 欄位 語言
DC.contributor資訊管理學系zh_TW
DC.creator徐郁齊zh_TW
DC.creatorYu-Chi Hsuen_US
dc.date.accessioned2023-8-17T07:39:07Z
dc.date.available2023-8-17T07:39:07Z
dc.date.issued2023
dc.identifier.urihttp://ir.lib.ncu.edu.tw:444/thesis/view_etd.asp?URN=110423012
dc.contributor.department資訊管理學系zh_TW
DC.description國立中央大學zh_TW
DC.descriptionNational Central Universityen_US
dc.description.abstract網路的快速發展,已派發的自治系統及 IP 地址數量龐大,其中,自治系統之間的 關係錯綜複雜,而自治系統之間藉由 BGP 協定交換路由資訊,BGP 協定本身並無附帶 之安全機制,於是迄今為止,出現許多惡意、非惡意的路由宣告,造成網際網路中發生 許多路由洩漏以及路由劫持,然而,陸續有許多防範 BGPHijack 的框架及方法,其中 最熱門、相較之下也最被廣為採用的即為 RPKI 框架,但時至今日,RPKI 的部署以及 ROA 的創建,在全球的路由之中仍然尚未到達半數以上,即代表網路中,多數路由之 ROV 結果,仍然為 NotFound,若將網路安全性作為第一優先考量,強硬地在邊界路由 器上設定只接收 RPKI-valid 之路由,則會大幅影響網路的連接性以及可達性。因此本 研究基於網路的連接性、可達性以及安全性之考量,設計並實作一套基於驗證路由資訊 一致性之自動化佈署 BGP 路由過濾策略的系統,持續監聽網路介面,過濾 BGP 封包, 並解析封包內容,並根據所收到的 BGPUpdateMessage,查詢 InternetRoutingRegistry 資料庫,根據該路由於分散式資料庫中的資訊,產生路由過濾策略,並將路由過濾策略 部署至自治系統內的邊界路由器,企圖在 RPKI-NotFound 之路由當中進一步過濾潛在的 惡意路由,避免將惡意路由收進路由表中,加以散播惡意路由資訊,以此提升自治系統 及整體網路安全性。zh_TW
dc.description.abstractWith the rapid development of the network, a large number of autonomous systems and IP addresses have been distributed. Among them, the relationship between the autonomous systems is intricate, and the routing information is exchanged between the autonomous systems through the BGP protocol. Today, the establishment of ROA has not yet reached more than half of the routes in the world, which means that most routes in the network have not yet registered ROA. Considering network security, if the border router is set to only accept RPKI-valid routes, it will greatly affect the connectivity and reachability of the network. Therefore, based on the consideration of network connectivity, reachability and security, this research designs and implements a set of automatic deployment BGP routing filtering policy system based on verifying the consistency of routing information. It continuously monitors the network interface, filters BGP packets, and analyzes the packet content. Leveraging data acquired from BGP neighbors, the system proficiently liaises with the IRR database. Proactively, it meticulously filters potential malicious routes, forestalling their entry into the routing table and inhibiting further propagation. This astute tactic significantly fortifies the security of autonomous systems, thus reinforcing the overall network′s robustness.en_US
DC.subjectBGPzh_TW
DC.subject路由過濾zh_TW
DC.subject軟體定義網路zh_TW
DC.subject自動化zh_TW
DC.subjectBGPen_US
DC.subjectRoute Filteringen_US
DC.subjectSoftwared-Defined Networken_US
DC.subjectAutomationen_US
DC.title設計與實作基於驗證路由資訊一致性之自動化 BGP 路由 過濾策略與安全機制zh_TW
dc.language.isozh-TWzh-TW
DC.titleDesign and Implementation of an Automated BGP Routing Filtering Strategy and Security Mechanism based on Validation of Route Information Consistencyen_US
DC.type博碩士論文zh_TW
DC.typethesisen_US
DC.publisherNational Central Universityen_US

若有論文相關問題,請聯絡國立中央大學圖書館推廣服務組 TEL:(03)422-7151轉57407,或E-mail聯絡  - 隱私權政策聲明