Accurate Real-time Identification of IP Prefix Hijacking
- 1 May 2007
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
- No. 10816011,p. 3-17
- https://doi.org/10.1109/sp.2007.7
Abstract
We present novel and practical techniques to accurately detect IP prefix hijacking attacks in real time to facilitate mitigation. Attacks may hijack victim's address space to disrupt network services or perpetrate malicious activities such as spamming and DoS attacks without disclosing identity. We propose novel ways to significantly improve the detection accuracy by combining analysis of passively collected BGP routing updates with data plane fingerprints of suspicious prefixes. The key insight is to use data plane information in the form of edge network fingerprinting to disambiguate suspect IP hijacking incidences based on routing anomaly detection. Conflicts in data plane fingerprints provide much more definitive evidence of successful IP prefix hijacking. Utilizing multiple real-time BGP feeds, we demonstrate the ability of our system to distinguish between legitimate routing changes and actual attacks. Strong correlation with addresses that originate spam emails from a spam honeypot confirms the accuracy of our techniques.Keywords
This publication has 15 references indexed in Scilit:
- Efficient Techniques for Detecting False Origin Advertisements in Inter-domain RoutingPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2006
- Understanding the network-level behavior of spammersACM SIGCOMM Computer Communication Review, 2006
- Origin authentication in interdomain routingPublished by Association for Computing Machinery (ACM) ,2003
- Topology-Based Detection of Anomalous BGP MessagesLecture Notes in Computer Science, 2003
- Distributing Authoritative Name Servers via Shared Unicast AddressesPublished by RFC Editor ,2002
- A technique for counting natted hostsPublished by Association for Computing Machinery (ACM) ,2002
- An investigation of geographic mapping techniques for internet hostsPublished by Association for Computing Machinery (ACM) ,2001
- Guidelines for creation, selection, and registration of an Autonomous System (AS)Published by RFC Editor ,1996
- Host Anycasting ServicePublished by RFC Editor ,1993
- TCP Extensions for High PerformancePublished by RFC Editor ,1992