• DocumentCode
    3310838
  • Title

    Buddyguard: A buddy system for fast and reliable detection of IP prefix anomalies

  • Author

    Jun Li ; Ehrenkranz, T. ; Elliott, Phillip

  • Author_Institution
    Univ. of Oregon, Eugene, OR, USA
  • fYear
    2012
  • fDate
    Oct. 30 2012-Nov. 2 2012
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    Due to operational malpractice or security attacks, an IP prefix (i.e., a block of IP addresses) can undergo many types of routing anomalies. Perhaps the most well-known of such anomalies is prefix hijacking, where an attacker hijacks traffic meant to reach the legitimate user of a prefix. Anomalies can also easily occur through route leaks, which can disrupt traffic for numerous prefixes at once. While various solutions have been proposed to detect such anomalies, these solutions are limited and susceptible to attacker countermeasures. In this paper we present Buddyguard, a new approach to detecting prefix anomalies including prefix hijacking and route leaks. Buddyguard compares the behavior of a monitored prefix with the behavior of a set of numerous buddy prefixes. The system detects anomalies when the behavior of the monitored prefix significantly diverges from that of its buddies. Our evaluation results show that Buddyguard provides fast, accurate and lightweight monitoring of IP prefix anomalies, and its introduction and use of buddy prefixes enables it to be resilient against resourceful attackers.
  • Keywords
    IP networks; authorisation; computer network security; telecommunication network routing; Buddyguard; IP addresses; IP prefix anomalies; buddy system; lightweight monitoring; operational malpractice; prefix hijacking; route leaks; routing anomalies; security attack; IP networks; Monitoring;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols (ICNP), 2012 20th IEEE International Conference on
  • Conference_Location
    Austin, TX
  • Print_ISBN
    978-1-4673-2445-8
  • Electronic_ISBN
    978-1-4673-2446-5
  • Type

    conf

  • DOI
    10.1109/ICNP.2012.6459962
  • Filename
    6459962