论文标题
SRV6:那里有人吗?
SRv6: Is There Anybody Out There?
论文作者
论文摘要
细分路由是一种现代形式的基于源的路由的形式,即是一种路由技术,其中所有路由决策的全部或部分都是由源或路径上的跳跃预定的。自2013年最初的标准化工作以来,细分市场的路线似乎已获得了实质性的行业和运营商的支持。特别是在IPv6(SRV6)上进行的细分路线,广告宣传了一些优点,可以轻松部署和灵活性网络的操作。但是,许多人认为,如果没有尽最大的谨慎,则尤其是部门路由和SRV6的部署会构成重大的安全威胁。在本文中,我们对互联网中的SRV6部署进行了首次实证分析。首先,我们分析了仿真环境中的SRV6行为,发现不同的SRV6实现有可能泄漏信息到外部。其次,我们在公开可用的路由收集器数据中搜索SRV6部署的迹象,但找不到任何痕迹。第三,我们开展大规模的示踪活动,以调查可能的SRV6部署。在SRV6的第一项实证研究中,即使对于声称已部署在其网络中的公司,我们也找不到SRV6部署的痕迹。缺乏泄漏可能表明部署SRV6时网络运营商遵循良好的安全惯例。
Segment routing is a modern form of source-based routing, i.e., a routing technique where all or part of the routing decision is predetermined by the source or a hop on the path. Since initial standardization efforts in 2013, segment routing seems to have garnered substantial industry and operator support. Especially segment routing over IPv6 (SRv6) is advertised as having several advantages for easy deployment and flexibility in operations in networks. Many people, however, argue that the deployment of segment routing and SRv6 in particular poses a significant security threat if not done with the utmost care. In this paper we conduct a first empirical analysis of SRv6 deployment in the Internet. First, we analyze SRv6 behavior in an emulation environment and find that different SRv6 implementations have the potential to leak information to the outside. Second, we search for signs of SRv6 deployment in publicly available route collector data, but could not find any traces. Third, we run large-scale traceroute campaigns to investigate possible SRv6 deployments. In this first empirical study on SRv6 we are unable to find traces of SRv6 deployment even for companies that claim to have it deployed in their networks. This lack of leakage might be an indication of good security practices being followed by network operators when deploying SRv6.