BGP hijackers can make ML-based detectors DFOH and BEAM miss forged-origin hijacks by injecting a few crafted announcements that poison the public monitoring data.
Global BGP Attacks that Evade Route Monitoring
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
As the deployment of comprehensive Border Gateway Protocol (BGP) security measures is still in progress, BGP monitoring continues to play a critical role in protecting the Internet from routing attacks. Fundamentally, monitoring involves observing BGP feeds to detect suspicious announcements and taking defensive action. However, BGP monitoring relies on seeing the malicious BGP announcement in the first place! In this paper, we develop a novel attack that can hide itself from all state-of-the-art BGP monitoring systems we tested while affecting the entire Internet. The attack involves launching a sub-prefix hijack with the RFC-specified NO_EXPORT community attached to prevent networks with the malicious route installed from sending the route to BGP monitoring systems. We study the viability of this attack at four tier-1 networks and find all networks we studied were vulnerable to the attack. Finally, we propose a mitigation that significantly improves the robustness of the BGP monitoring ecosystem. Our paper aims to raise awareness of this issue and offer guidance to providers to protect against such attacks.
citation-role summary
citation-polarity summary
fields
cs.CR 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
background 1representative citing papers
citing papers explorer
-
Is Crunching Public Data the Right Approach to Detect BGP Hijacks?
BGP hijackers can make ML-based detectors DFOH and BEAM miss forged-origin hijacks by injecting a few crafted announcements that poison the public monitoring data.