Detecting IP prefix Hijacking Using Data Reduction-Based and Binary Search Algorithm

被引:0
作者
Alshamrani, Hussain [1 ]
Ghita, Bogdan [1 ]
Lancaster, David [1 ]
机构
[1] Univ Plymouth, Ctr Secur Commun & Network Res CSCAN, Plymouth, Devon, England
来源
2015 INTERNET TECHNOLOGIES AND APPLICATIONS (ITA) PROCEEDINGS OF THE SIXTH INTERNATIONAL CONFERENCE (ITA 15) | 2015年
关键词
BGP advertisements; Binary Search Algorithm; Data Reduction; IP prefix; origin AS;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In spite of significant ongoing research, the Border gateway protocol (BGP) still encompasses conceptual vulnerability issues regarding impersonating the ownership of IP prefixes for ASes (Autonomous Systems). In this context, a number of research studies focused on securing BGP through historical-based and statistical-based behavioural models. This paper proposes a novel algorithm aiming to track the behaviour of BGP edge routers and detect IP prefix hijacks based on a typical signature. The algorithm parses the BGP advertisements in order to detect the apparent relocation of specific IP prefixes, either in the same or in different regions. The algorithm aims to identify IP prefixes by multiple independent ASes. The method differs from routing consistency monitoring, which faces difficulties detecting events at the edge of the BGP infrastructure. Based on the RIRs' database, the algorithm can detect national and cross-border IP prefix hijacks very quick. However, 5 results out of 16 were not accurate therefore the algorithm has some false positives and needs further improvement to be done in future.
引用
收藏
页码:78 / 84
页数:7
相关论文
共 12 条
  • [1] A. (Asia P. N. I. Centre), APNIC QUER APNIC WHO
  • [2] Balakrishnan H., 2009, YOUTUBE WAS HIJACKED
  • [3] CAO HY, 2009, 2009 IEEE INT C NETW, P192, DOI DOI 10.1109/NAS.2009.41
  • [4] Dalal A., 2004, SEARCHING SORTING AL, P1
  • [5] de Urbina Cazenave I. O., 2011, 2011 International Symposium on Innovations in Intelligent Systems and Applications (INISTA 2011), P107, DOI 10.1109/INISTA.2011.5946083
  • [6] Marsan C. D., 6 WORST INTERNET ROU
  • [7] MathWork, CELL ARR MATLAB SIM
  • [8] Meyer D., 2003, INDEX BGPDATA
  • [9] Rekhter Y., 1995, BORDER GATEWAY PROTO, P67
  • [10] Ripe, IND SOURC BGPDUMP