Pith. sign in

CAIR: Using Formal Languages to Study Routing, Leaking, and Interception in BGP

1 Pith paper cite this work. Polarity classification is still indexing.

1 Pith paper citing it
abstract

The Internet routing protocol BGP expresses topological reachability and policy-based decisions simultaneously in path vectors. A complete view on the Internet backbone routing is given by the collection of all valid routes, which is infeasible to obtain due to information hiding of BGP, the lack of omnipresent collection points, and data complexity. Commonly, graph-based data models are used to represent the Internet topology from a given set of BGP routing tables but fall short of explaining policy contexts. As a consequence, routing anomalies such as route leaks and interception attacks cannot be explained with graphs. In this paper, we use formal languages to represent the global routing system in a rigorous model. Our CAIR framework translates BGP announcements into a finite route language that allows for the incremental construction of minimal route automata. CAIR preserves route diversity, is highly efficient, and well-suited to monitor BGP path changes in real-time. We formally derive implementable search patterns for route leaks and interception attacks. In contrast to the state-of-the-art, we can detect these incidents. In practical experiments, we analyze public BGP data over the last seven years.

citation-role summary

background 1

citation-polarity summary

fields

cs.NI 1

years

2025 1

verdicts

CONDITIONAL 1

roles

background 1

polarities

unclear 1

representative citing papers

BEAR: BGP Event Analysis and Reporting

cs.NI · 2025-06-04 · conditional · novelty 7.0

A new LLM-based framework automatically produces explanatory reports for BGP hijack and route leak events, claiming 100% accuracy over 54 real and synthetic samples.

citing papers explorer

Showing 1 of 1 citing paper.

  • BEAR: BGP Event Analysis and Reporting cs.NI · 2025-06-04 · conditional · none · ref 18 · internal anchor

    A new LLM-based framework automatically produces explanatory reports for BGP hijack and route leak events, claiming 100% accuracy over 54 real and synthetic samples.