• DocumentCode
    1952608
  • Title

    Detecting bogus BGP route information: Going beyond prefix hijacking

  • Author

    Qiu, Jian ; Gao, Lixin ; Ranjan, Supranamaya ; Nucci, Antonio

  • Author_Institution
    Department of ECE, Univ. of Massachusetts, Amherst, 01003, USA
  • fYear
    2007
  • fDate
    17-21 Sept. 2007
  • Firstpage
    381
  • Lastpage
    390
  • Abstract
    Border Gateway Protocol (BGP) is the de facto inter-domain routing protocol of the Internet. However, the BGP system has been built based on the implicit trust among individual administrative domains and no countermeasure prevents bogus routes from being injected and propagated through the system. Attackers might exploit bogus routes to gain control of arbitrary address spaces (i.e. prefixes), to either hijack the relevant traffic or launch stealthy attacks. Attackers can directly originate the bogus routes of the prefixes, or even stealthier, further spoof the AS paths of the routes to make them appear to be originated by others. We propose a real-time detection system for ISPs to provide protection against bogus routes. The system learns from the historical BGP routing data the basic routing information objects that assemble BGP routes, and detect the suspicious routes comprised of unseen objects. In particular, we leverage a directed AS-link topology model to detect path spoofing routes that violate import/export routing policies. Moreover, we explore various heuristics to infer the potentially legitimate routing information objects to reduce false alarms. The experiments based on several documented incidents show that our system can yield a nearly 100% detection rate while bounding the false positive rate to as low as 0.02%.
  • Keywords
    Assembly; Gain control; Internet; Object detection; Peer to peer computing; Protection; Real time systems; Routing protocols; Topology; Traffic control;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy in Communications Networks and the Workshops, 2007. SecureComm 2007. Third International Conference on
  • Conference_Location
    Nice, France
  • Print_ISBN
    978-1-4244-0974-7
  • Electronic_ISBN
    978-1-4244-0975-4
  • Type

    conf

  • DOI
    10.1109/SECCOM.2007.4550358
  • Filename
    4550358