REVIEW 2 cited by
Global BGP Attacks that Evade Route Monitoring
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
As the deployment of comprehensive Border Gateway Protocol (BGP) security measures is still in progress, BGP monitoring continues to play a critical role in protecting the Internet from routing attacks. Fundamentally, monitoring involves observing BGP feeds to detect suspicious announcements and taking defensive action. However, BGP monitoring relies on seeing the malicious BGP announcement in the first place! In this paper, we develop a novel attack that can hide itself from all state-of-the-art BGP monitoring systems we tested while affecting the entire Internet. The attack involves launching a sub-prefix hijack with the RFC-specified NO_EXPORT community attached to prevent networks with the malicious route installed from sending the route to BGP monitoring systems. We study the viability of this attack at four tier-1 networks and find all networks we studied were vulnerable to the attack. Finally, we propose a mitigation that significantly improves the robustness of the BGP monitoring ecosystem. Our paper aims to raise awareness of this issue and offer guidance to providers to protect against such attacks.
Forward citations
Cited by 2 Pith papers
-
Data-Plane Telemetry to Mitigate Long-Distance BGP Hijacks
HiDe detects long-distance BGP interception attacks by watching per-prefix minimum round-trip times for sudden sustained jumps, using a geolocation-based lower-bound threshold, and it runs at line rate on a Tofino2 pr...
-
Is Crunching Public Data the Right Approach to Detect BGP Hijacks?
BGP hijackers can make ML-based detectors DFOH and BEAM miss forged-origin hijacks by injecting a few crafted announcements that poison the public monitoring data.
Discussion (0). Continue with ORCID to comment.