Title :
Separating wheat from chaff: Winnowing unintended prefixes using machine learning
Author :
Lutu, Andra ; Bagnulo, Marcelo ; Cid-Sueiro, Jesus ; Maennel, Olaf
Author_Institution :
Inst. IMDEA Networks, Madrid, Spain
fDate :
April 27 2014-May 2 2014
Abstract :
In this paper, we propose the use of prefix visibility at the interdomain level as an early symptom of anomalous events in the Internet. We focus on detecting anomalies which, despite their significant impact on the routing system, remain concealed from state of the art tools. We design a machine learning system to winnow the prefixes with unintended limited visibility - symptomatic of anomalous events - from the prefixes with intended limited visibility - resulting from legitimate routing operations. We train a winnowing algorithm with ground-truth data on 20,000 operational limited visibility prefixes (LVPs) already classified by the operators of the origin networks. The ground-truth was collected using the BGP Visibility Scanner, a tool we developed to provide operators with a multi-angle view on the efficacy of their routing policies. We build a dataset with the pre-classified prefixes and the features describing their visibility status dynamics. We further use this dataset to derive a boosted decision tree which winnows unintended LVPs with an accuracy of 95%.
Keywords :
Internet; computer network security; decision trees; internetworking; learning (artificial intelligence); routing protocols; BGP visibility scanner; Internet; anomalous events; anomaly detection; boosted decision tree; border gateway protocol; ground-truth data; intended limited visibility; interdomain level; legitimate routing operations; machine learning system; operational limited visibility prefixes; preclassified prefixes; routing policies; routing system; unintended LVP; unintended limited visibility; visibility status dynamics; winnowing algorithm; Algorithm design and analysis; Feeds; Internet; Machine learning algorithms; Monitoring; Routing; Training;
Conference_Titel :
INFOCOM, 2014 Proceedings IEEE
Conference_Location :
Toronto, ON
DOI :
10.1109/INFOCOM.2014.6848023