Practical defenses against BGP prefix hijacking
Prefix
Border Gateway Protocol
Promotion (chess)
Peering
DOI:
10.1145/1364654.1364658
Publication Date:
2008-04-29T09:04:11Z
AUTHORS (4)
ABSTRACT
Prefix hijacking, a misbehavior in which misconfigured or malicious BGP router originates an IP prefix that the does not own, is becoming increasingly serious security problem on Internet. In this paper, we conduct first comprehensive study incrementally deployable mitigation solutions against hijacking. We propose novel reactive detection-assisted solution based idea of bogus route purging and valid promotion. Our simulations realistic settings show routes at 20 highest-degree ASes reduces polluted portion Internet by random hijack from 50% down to 24%, adding promotion further remaining pollution 33% ~ 57%, prove our proposed scheme preserve convergence properties regardless number promoters. are demonstrate detection systems limited feeds subject evasion hijackers. Motivated need for proactive defenses complement response, evaluate customer filtering, best common practice among large ISPs today, its effectiveness. also added benefits combining purging-promotion with filtering.
SUPPLEMENTAL MATERIAL
Coming soon ....
REFERENCES (0)
CITATIONS (41)
EXTERNAL LINKS
PlumX Metrics
RECOMMENDATIONS
FAIR ASSESSMENT
Coming soon ....
JUPYTER LAB
Coming soon ....