Threat Model for BGP Path Security
暂无分享,去创建一个
This document describes a threat model for the context in which
External Border Gateway Protocol (EBGP) path security mechanisms will
be developed. The threat model includes an analysis of the Resource
Public Key Infrastructure (RPKI) and focuses on the ability of an
Autonomous System (AS) to verify the authenticity of the AS path info
received in a BGP update. We use the term "PATHSEC" to refer to any
BGP path security technology that makes use of the RPKI. PATHSEC will
secure BGP, consistent with the inter-AS security focus of the RPKI.
The document characterizes classes of potential adversaries that are
considered to be threats and examines classes of attacks that might be
launched against PATHSEC. It does not revisit attacks against
unprotected BGP, as that topic has already been addressed in the BGP-4
standard. It concludes with a brief discussion of residual
vulnerabilities.