Logo do repositório
 
Publicação

Securing the Internet at the Exchange Points

datacite.subject.fosDepartamento de Informáticapt_PT
dc.contributor.advisorBessani, Alysson Neves, 1978-
dc.contributor.advisorRamos, Fernando Manuel Valente
dc.contributor.authorVale, Tomás Joaquim Gonçalves Peixinho do
dc.date.accessioned2023-03-27T11:58:06Z
dc.date.available2023-03-27T11:58:06Z
dc.date.issued2023
dc.date.submitted2022
dc.descriptionTese de mestrado, Engenharia Informática (Arquitectura, Sistemas e Redes de Computadores), 2022, Universidade de Lisboa, Faculdade de Ciênciaspt_PT
dc.description.abstractBGP, the border gateway protocol, is the inter-domain routing protocol that glues the Internet. Despite its importance, it has well-known security problems. Frequently, the BGP infrastructure is the target of prefix hijacking and path manipulation attacks. These attacks disrupt the normal functioning of the Internet by either redirecting the traffic, potentially allowing eavesdropping, or even preventing it from reaching its destination altogether, affecting availability. These problems result from the lack of a fundamental security mechanism: the ability to validate the information in routing announcements. Specifically, it does not authenticate the prefix origin nor the validity of the announced routes. This means that an intermediate network that intercepts a BGP announcement can maliciously announce an IP prefix that it does not own as theirs, or insert a bogus path to a prefix with the goal to intercept traffic. Several solutions have been proposed in the past, but they all have limitations, of which the most severe is arguably the requirement to perform drastic changes on the existing BGP infrastructure (i.e., requiring the replacement of existing equipment). In addition, most solutions require their widespread adoption to be effective. Finally, they typically require secure communication channels between the participant routers, which entails computationally-intensive cryptographic verification capabilities that are normally unavailable in this type of equipment. With these challenges in mind, this thesis proposes to investigate the possibility to improve BGP security by leveraging the software-defined networking (SDN) technology that is increasingly common at Internet Exchange Points (IXPs). These interconnection facilities are single locations that typically connect hundreds to thousands of networks, working as Internet “middlemen” ideally placed to implement inter-network mechanisms, such as security, without requiring changes to the network operators’ infrastructure. Our key idea is to include a secure channel between IXPs that, by running in the SDN server that controls these modern infrastructures, avoids the cryptographic requirements in the routers. In our solution, the secure channel for communication implements a distributed ledger (a blockchain), for decentralized trust and its other inherent guarantees. The rationale is that by increasing trust and avoiding expensive infrastructure updates, we hope to create incentives for operators to adhere to these new IXP-enhanced security services.pt_PT
dc.identifier.tid203493672
dc.identifier.urihttp://hdl.handle.net/10451/56826
dc.language.isoengpt_PT
dc.subjectBGPpt_PT
dc.subjectIXPpt_PT
dc.subjectSDNpt_PT
dc.subjectASpt_PT
dc.subjectsegurançapt_PT
dc.subjectprotocolo de roteamentopt_PT
dc.subjectroubo de prefixopt_PT
dc.subjectmanipulação de rotaspt_PT
dc.subjectblockchainpt_PT
dc.subjectsmart contractpt_PT
dc.subjectHyperledger Fabricpt_PT
dc.subjectTeses de mestrado - 2023pt_PT
dc.titleSecuring the Internet at the Exchange Pointspt_PT
dc.typemaster thesis
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typemasterThesispt_PT
thesis.degree.nameTese de mestrado, Engenharia Informática (Arquitectura, Sistemas e Redes de Computadores)pt_PT

Ficheiros

Principais
A mostrar 1 - 1 de 1
A carregar...
Miniatura
Nome:
TM_Tomás_Vale.pdf
Tamanho:
2.44 MB
Formato:
Adobe Portable Document Format
Licença
A mostrar 1 - 1 de 1
Miniatura indisponível
Nome:
license.txt
Tamanho:
1.2 KB
Formato:
Item-specific license agreed upon to submission
Descrição: