usenix conference policies
Towards a Framework for Evaluating BGP Security
Olaf Maennel and Iain Phillips, Loughborough University; Debbie Perouli, Purdue University; Randy Bush, Internet Initiative Japan; Rob Austein, Dragon Research Labs; Askar Jaboldinov, Loughborough University
Security and performance evaluation of Internet protocols can be greatly aided by emulation in realistic deployment scenarios. We describe our implementation of such methods which uses high-level abstractions to bring simplicity into a virtualized test-lab.
We argue that current test-labs have not adequately captured those challenges, partly because their design is too static. To achieve more flexibility and to allow the experimenter to easily deploy many alternative scenarios we need abstractions that allow auto-configuration and auto-deployment of real router and server code in a multi-AS infrastructure. We need to be able to generate scenarios for multi-party players in a fully isolated emulated test-lab and deploy the network using virtualized routers, switches, and servers.
In this paper, our abstractions are specifically designed to evaluate the BGP security framework currently being documented by the IETF SIDR working group. We capture the relevant aspects of the SIDR security proposals, and allow experimenters to evaluate the technology in topologies of real router and server code. We believe such methods are also useful for teaching newcomers and operators, as it allows them to gain experience in a sandbox before deployment. It allows security experts to set up controlled experiments at various levels of complexity, and concentrate on discovering weaknesses, instead of having to spend time on tedious configuration tasks. Finally, it allows router vendors and implementers to test their code and to perform scalability evaluation.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
title = {Towards a Framework for Evaluating {BGP} Security},
booktitle = {5th Workshop on Cyber Security Experimentation and Test (CSET 12)},
year = {2012},
address = {Bellevue, WA},
url = {https://www.usenix.org/conference/cset12/workshop-program/presentation/Maennel},
publisher = {USENIX Association},
month = aug
}
connect with us