A study of prefix hijacking and interception in the Internet

被引:116
作者
Ballani, Hitesh [1 ]
Francis, Paul [1 ]
Zhang, Xinyang [1 ]
机构
[1] Cornell Univ, Ithaca, NY 14853 USA
关键词
measurement; security; routing; BGP; hijacking; interception;
D O I
10.1145/1282427.1282411
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There have been many incidents of prefix hijacking in the Internet. The hijacking AS can blackhole the hijacked traffic. Alternatively, it can transparently intercept the hijacked traffic by forwarding it onto the owner. This paper presents a study of such prefix hijacking and interception with the following contributions: (1). We present a methodology for prefix interception, (2). We estimate the fraction of traffic to any prefix that can be hijacked and intercepted in the Internet today, (3). The interception methodology is implemented and used to intercept real traffic to our prefix, (4). We conduct a detailed study to detect ongoing prefix interception. We find that: Our hijacking estimates are in line with the impact of past hijacking incidents and show that ASes higher up in the routing hierarchy can hijack a significant amount of traffic to any prefix, including popular prefixes. A less apparent result is that the same holds for prefix interception too. Further, our implementation shows that intercepting traffic to a prefix in the Internet is almost as simple as hijacking it. Finally, while we fail to detect ongoing prefix interception, the detection exercise highlights some of the challenges posed by the prefix interception problem.
引用
收藏
页码:265 / 276
页数:12
相关论文
共 47 条
  • [1] AIELLO W, 2003, P C COMP COMM SEC CC
  • [2] [Anonymous], ALEXA TOP SITES
  • [3] [Anonymous], 2003, P NDSS
  • [4] [Anonymous], QUAGGA ROUTING SUITE
  • [5] [Anonymous], 3924 RFC
  • [6] [Anonymous], P SEC SYST NETW
  • [7] [Anonymous], 2004, P ACM SIGCOMM
  • [8] BOOTHE P, 2006, NANOG 36 M
  • [9] BROIDO A, 2001, P NETW REL DAT MAN N
  • [10] PlanetLab: An overlay testbed for broad-coverage services
    Chun, B
    Culler, D
    Roscoe, T
    Bavier, A
    Peterson, L
    Wawrzoniak, M
    Bowman, M
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2003, 33 (03) : 3 - 12