Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Note: If you are using a GUI version of Ubuntu, you should disable networking by unchecking uncheck "" it in the relevant menu, as shown in Figure 3, in order to avoid interfaces swapping IP addresses!

Image Added

Fig. 3: Uncheck "Enable Networking".

Load the network configuration with onos-netcfg and login to the onos CLI:

...

Now the hijacker (AS65003) will attract all the traffic away from AS65001 (destined to 40.0.0.0/8); at the same time, the ExaBGP speaker will send the BGP update of the hijack (among other updates seen by AS65004) to the ONOS instance (running ARTEMIS) and the hijack will be detected. Checking the logs, you will see that the attack is actually detected and the deaggregation mechanism has successfully mitigated the attack (by announcing the more specific prefixes 40.0.0.0/9 and 40.128.0.0/9 from the BGP speaker of the protected AS). After BGP converges and the control and data planes are consistent, the traffic of AS65001, destined to 40.0.0.0/8, returns to the protected AS.

Demo video

 

 

 













Fig. 34: The fully emulated demo topology.

...