Title :
Customer-side detection of Internet-scale traffic redirection
Author :
Salvador, Paulo ; Nogueira, Antonio
Author_Institution :
DETI, Univ. of Aveiro, Aveiro, Portugal
Abstract :
Recent reports of Internet-scale traffic redirection based on BGP route hijacking, for perpetration of man-in-the-middle (at distance) attacks, have put major institutions and network service providers in alert. However, corporate customers have to content with a helpless bystander and victim roles due to the lack of tools to detect and counter-act Internet-scale traffic redirection. An world-wide redirection of target traffic will compromise unencrypted communications and allow the deployment of various attacks on encrypted communications. This paper proposes a world-wide distributed probing methodology to detect traffic routing variations. Upon detection, a corporate customer cannot act in terms of Internet-scale routing but can warn its network service providers and request consequent actions. Nevertheless, upon warning, the corporate customer can locally deploy extreme security policies, like terminating sensible deferrable communications (database/information synchronization, audio/video calls) and increasing the required encryption level for public services. The proposed solution is easily deployed and has a very low implementation cost. The proof-of-concept presented in this paper uses worldwide deployed probes to detected specific traffic redirection. The results obtained reveal that the proposed methodology, due to this world-wide spreading of the probes and joint analysis of measurements, is able: (i) to detect Internet-scale traffic redirection attacks, and (ii) ignore localized licit inner-AS rerouting.
Keywords :
Internet; protocols; telecommunication network routing; BGP route hijacking; Internet-scale routing; Internet-scale traffic redirection attacks; border gateway protocol; corporate customers; customer-side detection; encryption level; localized licit inner-AS rerouting; man-in-the-middle attacks; target traffic; traffic routing variations; world-wide distributed probing methodology; world-wide redirection; IP networks; Monitoring; Probes; Relays; Routing; Silicon compounds; Time measurement; Attack detection; BGP routes hijacking; Internet-scale traffic redirection; at distance man-in-the-middle attacks;
Conference_Titel :
Telecommunications Network Strategy and Planning Symposium (Networks), 2014 16th International
Conference_Location :
Funchal
DOI :
10.1109/NETWKS.2014.6958532