BGPay:一种用于BGP劫持过滤的激励兼容机制
BGPay: An Incentive-Compatible Mechanism for BGP Hijack Filtering
浏览论文内容
中文总结 AI 辅助
针对BGP劫持防御的激励不匹配问题,提出基于市场的BGPay托管协议,利用公共路由收集器的路由表作为信任根,通过智能合约按遏制影响支付奖励以实现激励兼容。
中文摘要 AI 辅助
BGP劫持仍是持续存在的威胁,因为现有防御措施包括RPKI/ROV存在根本的激励不匹配:最适合过滤恶意通告的网络承担运营成本却无直接收益,而受害前缀所有者获得全部价值。我们倡导一种基于市场的替代方案,即前缀所有者为过滤其前缀的无效通告设置固定赏金,将过滤从利他行为转变为私人交易。我们的核心见解是,传播中的劫持及其缺失都无法避开公共路由收集器,其提交的路由表可成为释放赏金资金的独立信任根。我们基于此见解设计了BGPay,这是一种托管协议,其中过滤方和监测方在任何一方披露前做出承诺,智能合约依据证据而非前缀所有者的判断进行支付。通过分析1000起真实劫持事件,我们发现当前的收集器已在关键区域提供了足够的可见性:对遏制劫持更重要的自治系统(AS)在公共监测点也具有高度可见性。因此,按遏制影响比例设置奖励可阻止不当行为。
英文摘要
BGP hijacking remains a persistent threat as existing defenses, including RPKI/ROV suffer from a fundamental incentive misalignment: the networks best positioned to filter malicious announcements bear operational costs but receive no direct benefit, while the victim prefix owner captures all the value. We advocate a market-based alternative in which prefix owners post standing bounties for filtering invalid announcements of their prefixes, turning filtering from altruism into a private transaction. Our insight is that neither a propagating hijack nor its absence can hide from public route collectors, whose committed routing tables could become an independent root of trust for releasing funds of the bounty. We build on this insight to design BGPay, an escrow protocol in which filterers and monitors commit before either reveals, and a smart contract pays out on evidence rather than on the prefix owner's judgment. Analyzing 1K real hijack incidents, we find that today's collectors already provide enough visibility where it matters: ASes that are more important for containing the hijack are also highly visible from the public monitors. Hence, setting rewards proportionately to containment impact discourages misbehavior.