Pith. sign in

REVIEW 2 cited by

Global BGP Attacks that Evade Route Monitoring

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2408.09622 v1 pith:BDGUBGAX submitted 2024-08-19 cs.CR cs.NI

classification cs.CRcs.NI
keywords monitoringattackattacksnetworksrouteinternetinvolvesmalicious
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

As the deployment of comprehensive Border Gateway Protocol (BGP) security measures is still in progress, BGP monitoring continues to play a critical role in protecting the Internet from routing attacks. Fundamentally, monitoring involves observing BGP feeds to detect suspicious announcements and taking defensive action. However, BGP monitoring relies on seeing the malicious BGP announcement in the first place! In this paper, we develop a novel attack that can hide itself from all state-of-the-art BGP monitoring systems we tested while affecting the entire Internet. The attack involves launching a sub-prefix hijack with the RFC-specified NO_EXPORT community attached to prevent networks with the malicious route installed from sending the route to BGP monitoring systems. We study the viability of this attack at four tier-1 networks and find all networks we studied were vulnerable to the attack. Finally, we propose a mitigation that significantly improves the robustness of the BGP monitoring ecosystem. Our paper aims to raise awareness of this issue and offer guidance to providers to protect against such attacks.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Data-Plane Telemetry to Mitigate Long-Distance BGP Hijacks

    cs.NI 2025-07 conditional novelty 6.0 of 10

    HiDe detects long-distance BGP interception attacks by watching per-prefix minimum round-trip times for sudden sustained jumps, using a geolocation-based lower-bound threshold, and it runs at line rate on a Tofino2 pr...

  2. Is Crunching Public Data the Right Approach to Detect BGP Hijacks?

    cs.CR 2025-07 conditional novelty 5.0 of 10

    BGP hijackers can make ML-based detectors DFOH and BEAM miss forged-origin hijacks by injecting a few crafted announcements that poison the public monitoring data.

Pith tools