论文标题
确保互联网应用程序免于路由攻击
Securing Internet Applications from Routing Attacks
论文作者
论文摘要
假设对手丢弃流量或执行窃听的对手,通常会通过可用性和机密性的镜头来查看互联网路由的攻击。但是,战略对手可以使用路由攻击来损害TOR,证书局和比特币网络等关键Internet应用程序的安全性。在本文中,我们调查了这种特定应用程序的路由攻击,并认为应用程序层和网络层防御是必不可少的,急需的。虽然在短期内更容易部署应用程序层防御,但我们希望我们的工作能够为部署网络防御提供急需的动力。
Attacks on Internet routing are typically viewed through the lens of availability and confidentiality, assuming an adversary that either discards traffic or performs eavesdropping. Yet, a strategic adversary can use routing attacks to compromise the security of critical Internet applications like Tor, certificate authorities, and the bitcoin network. In this paper, we survey such application-specific routing attacks and argue that both application-layer and network-layer defenses are essential and urgently needed. While application-layer defenses are easier to deploy in the short term, we hope that our work serves to provide much needed momentum for the deployment of network-layer defenses.