Abstract
Keywords
Introduction
Routing determines how packets are forwarded between interconnected IP networks. Routers make these forwarding decisions from the routing information maintained in their routing tables, which identify reachable networks and the paths available to them. In enterprise and service-provider environments, routing protocols are responsible for learning and exchanging this information. Their behavior therefore has a direct effect on path selection, convergence, and overall network availability. The exchange of routing information allows routers to identify suitable paths from a source network to a destination network. Each routing protocol follows its own rules for discovering routes, evaluating alternative paths, and updating the routing table. These processes enable routers to respond to changes in network connectivity and maintain communication across multiple IP networks [1].
Open Shortest Path First (OSPF) is a link-state Interior Gateway Protocol (IGP) used for routing within an autonomous system. It applies the Shortest Path First (SPF) calculation based on Dijkstra’s algorithm to determine the lowest-cost paths to known destinations. OSPF organizes a network into areas, with the backbone identified as Area 0. Routers maintain detailed link-state information for their own area, while communication between areas is handled through the OSPF hierarchical structure [2]. This organization limits the amount of topology information that must be maintained by every router and can reduce routing-table and link-state database overhead. OSPF uses interface cost, commonly derived from bandwidth, as the metric for path calculation and exchanges link-state information among neighboring routers to maintain a consistent view of the network topology. When OSPF is configured on the routers, it shares the whole topology of the network among all the neighboring routers by exchanging link state information. OSPF is considered to be an efficient routing protocol due to its capability of fast convergence and scalability. OSPF has good built in mechanisms for security but still there are some vulnerabilities in the protocol [6].
This research has focused on the security features of OSPF routing protocol. Initially a brief introduction of OSPF is presented and related work in this particular topic is discussed. In the second segment the primary emphasis is on security mechanism which is implemented in OSPF routing protocol. In this phase the authentication mechanism, Hierarchical Routing Mechanism and fight back mechanism in case of Fake LSA is mainly discussed. In third phase, OSPF internal and external security threats have been identified and appropriate remedial measures have been proposed.
Noninvasive methods have been used for threat detection in the network running OSPF protocol. A network topology has been designed in simulated software GNS3 with two cisco routers with complete configurations of hashing algorithm MD5 to secure the source and destination packets have been implanted. With the help of this algorithm unauthorized user is unable to tempered data. Digital signature with link encryption is also anther method which must be integrated to advance and secure the network end to end. After implementation of these two methods routing network of OSPF is safe and reliable.
Complete Article
The complete article, including all figures, tables, equations and algorithms, is available in the official publication PDF.
Conclusion
Routing information of all neighbors routers must be securely and accurately delivered which is usually circulated by the OSPF routing protocol. Digital signature techniques can be used to secure and protect the source integrity and authenticity. This research article elaborated a design in which digital signatures integrated with the LSA data. This design protects the routing database from internal and external invaders also secure interior causes of error, specially the contributors in the protocol which are supposed to be unsecure. Another concept of implementation of hashing algorithm MD5 using simulator GNS3 has been configured on routers using OSPF routing protocols. Router are presented to circulate the hashing algorithm to all other routers which are in the area of autonomous system through the flooding method of OSPF. A reliable authentication of binding among the router ID and public key. This authentication must be included in the OSPF Area 0. After implementation of all above techniques and mechanisms routing information is secure and has ability to protect from DOS (denial of Service) attacks. Somehow, still have some advance level attacks through which routing information may be modified and traceable.
References
- E. Kaffashi, A. M. Mousavi, H. R. Rahvard, S. H. Bojnordi, F. Khademsadegh, and S. Amirian, “A new attack on link-state database in Open Shortest Path First routing protocol, ” Journal of Electrical and Electronic Engineering, vol. 3, no. 2-1, pp. 39-45, 2014. doi: 10.11648/j.jeee.s.2015030201.19
- S. L. Murphy and M. R. Badger, “Digital signature protection of the OSPF routing protocol, ” in Proceedings of the Network and Distributed System Security Symposium (NDSS), pp. 93-102, 1996. doi: 10.1109/NDSS.1996.492416
- R. J. Perlman, “Network layer protocols with Byzantine robustness, ” Ph. D. dissertation, Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, MA, USA, 1988.
- B. Kumar and J. Crowcroft, “Integrating security in inter-domain routing protocols, ” ACM SIGCOMM Computer Communication Review, vol. 23, no. 5, pp. 36-51, 1993. doi: 10.1145/165611.165615
- G. G. Finn, Reducing the Vulnerability of Dynamic Computer Networks, ISI Research Report ISI/RR-88-201, Information Sciences Institute, University of Southern California, Marina del Rey, CA, USA, Jun. 1988.
- A. A. Vladimirov, K. V. Gavrilenko, J. N. Vizulis, and A. A. Mikhailovsky, Hacking Exposed Cisco Networks: Cisco Security Secrets & Solutions. New York, NY, USA: McGraw-Hill/Osborne, 2006.
- S. Waichal and B. B. Meshram, “Router attacks: Detection and defense mechanisms, ” International Journal of Scientific & Technology Research, vol. 2, no. 6, pp. 145-149, 2013.
- W. Odom, CCNP ROUTE 642-902 Official Certification Guide, 1st ed. Indianapolis, IN, USA: Cisco Press, 2010.
- G. Nakibly, E. Menahem, A. Waizel, and Y. Elovici, “Owning the routing table-Part II, ” presented at Black Hat USA, Las Vegas, NV, USA, 2013.
- Cisco Systems, “Configuring BGP, ” in Cisco IOS IP Configuration Guide, Release 12.2. Cisco Systems, 2006. [Online]. Available: https://www.cisco.com/c/en/us/td/docs/ios/12_2/ip/configuration/guide/fipr_c/1cfbgp.html. Accessed: Feb. 8, 2019.
- F. Le, G. G. Xie, and H. Zhang, “Understanding route redistribution, ” in Proceedings of the IEEE International Conference on Network Protocols (ICNP), pp. 81-92, 2007. doi: 10.1109/ICNP.2007.4375839
- D. F. Asigbe, A. M. Mustapha, C. C. M. Agbesi, B. F. Ephraim, A. S. K. Bright, and S. Clement, “Performance analysis of Interior Gateway Routing Protocol (EIGRP) over Open Shortest Path First (OSPF) protocol, ” International Journal of Scientific & Technology Research, vol. 5, no. 9, pp. 111-117, 2016.
- S. Vissicchio, L. Vanbever, L. Cittadini, G. G. Xie, and O. Bonaventure, “Safe routing reconfigurations with route redistribution, ” in Proceedings of IEEE INFOCOM, pp. 199-207, 2014. doi: 10.1109/INFOCOM.2014.6847940
- R. Graziani and A. Johnson, Routing Protocols and Concepts: CCNA Exploration Companion Guide. Indianapolis, IN, USA: Cisco Press, 2008, ch. 3, “Introduction to Dynamic Routing Protocols.”
- S. G. Thorenoor, “Dynamic routing protocol implementation decision between EIGRP, OSPF and RIP based on technical background using OPNET Modeler, ” in Proceedings of the 2nd International Conference on Computer and Network Technology (ICCNT), pp. 191-195, 2010. doi: 10.1109/ICCNT.2010.66
- Z.-Z. Wei and F. Wang, “Achieving resilient routing through redistributing routing protocols, ” in Proceedings of the IEEE International Conference on Communications (ICC), pp. 1-5, 2011. doi: 10.1109/ICC.2011.5962605
- S. S. Samaan, “Performance evaluation of RIPng, EIGRPv6 and OSPFv3 for real-time applications, ” Journal of Engineering, vol. 24, no. 1, pp. 111-122, 2018. doi: 10.31026/j.eng.2018.01.08
- S. A. Alabady, S. Hazim, and A. Amer, “Performance evaluation and comparison of dynamic routing protocols for suitability and reliability, ” International Journal of Grid and Distributed Computing, vol. 11, no. 7, pp. 41-52, 2018. doi: 10.14257/ijgdc.2018.11.7.05
- S. Naseer, Y. Saleem, S. Khalid, M. K. Bashir, J. Han, M. M. Iqbal, and K. Han, “Enhanced network anomaly detection based on deep neural networks, ” IEEE Access, vol. 6, pp. 48231-48246, 2018. doi: 10.1109/ACCESS.2018.2863036
- S. Naseer and Y. Saleem, “Enhanced network intrusion detection using deep convolutional neural networks, ” KSII Transactions on Internet and Information Systems, vol. 12, no. 10, pp. 5159-5178, 2018. doi: 10.3837/tiis.2018.10.028
- A. Arsalan and R. A. Rehman, “Interest broadcasting and timing attack in IoV (IBTA-IoV): A novel architecture using Named Software Defined Network, ” Computer Networks, vol. 213, Art. no. 109121, 2022. doi: 10.1016/j.comnet.2022.109121
- H. Sawalmeh, M. Malayshi, S. Ahmad, and A. Awad, “VPN remote access OSPF-based VPN security vulnerabilities and counter measurements, ” in Proceedings of the 2021 International Conference on Innovation and Intelligence for Informatics, Computing, and Technologies (3ICT), pp. 236-241, 2021. doi: 10.1109/3ICT53449.2021.9581512
- X. Zhu, W. Bao, J. Zhang, Y. Jiang, and H. Ma, “Research and analysis on the vulnerability of OSPF routing protocol, ” Journal of Cyber Security, vol. 8, no. 2, pp. 42-53, 2023. doi: 10.19363/J.cnki.cn10-1380/tn.2023.03.04
- X. Gomes, J. Fonseca, and R. Valadas, “Open Shortest Path First extension for the support of multiarea networks with arbitrary topologies, ” IET Networks, vol. 13, no. 3, pp. 241-248, 2024. doi: 10.1049/ntw2.12112