• DocumentCode
    1130520
  • Title

    An Online Mechanism for BGP Instability Detection and Analysis

  • Author

    Deshpande, Shivani ; Thottan, Marina ; Ho, Tin Kam ; Sikdar, Biplab

  • Author_Institution
    BlueCoat Syst., Sunnyvale, CA, USA
  • Volume
    58
  • Issue
    11
  • fYear
    2009
  • Firstpage
    1470
  • Lastpage
    1484
  • Abstract
    The importance of border gateway protocol (BGP) as the primary interautonomous system (AS) routing protocol that maintains the connectivity of the Internet imposes stringent stability requirements on its route selection process. Accidental and malicious activities such as misconfigurations, failures, and worm attacks can induce severe BGP instabilities leading to data loss, extensive delays, and loss of connectivity. In this work, we propose an online instability detection architecture that can be implemented by individual routers. We use statistical pattern recognition techniques for detecting the instabilities, and the algorithm is evaluated using real Internet data for a diverse set of events including misconfiguration, node failures, and several worm attacks. The proposed scheme is based on adaptive segmentation of feature traces extracted from BGP update messages and exploiting the temporal and spatial correlations in the traces for robust detection of the instability events. Furthermore, we use route change information to pinpoint the culprit ASes where the instabilities have originated.
  • Keywords
    Internet; internetworking; network servers; pattern recognition; routing protocols; security of data; statistical analysis; Internet; accidental activities; adaptive segmentation; border gateway protocol; culprit ASes; data loss; extensive delays; feature traces; malicious activities; node failures; online mechanism; primary interautonomous system routing protocol; robust detection; route selection process; spatial correlations; statistical pattern recognition techniques; temporal correlations; update messages; Data mining; Event detection; Feature extraction; Internet; Pattern recognition; Principal component analysis; Robust stability; Routing protocols; Stability analysis; Telecommunication traffic; Tin; BGP; anomaly detection; routing instability; statistical pattern recognition.;
  • fLanguage
    English
  • Journal_Title
    Computers, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9340
  • Type

    jour

  • DOI
    10.1109/TC.2009.91
  • Filename
    5161252