• DocumentCode
    2306491
  • Title

    IP prefix hijacking detection using the collection of as characteristics

  • Author

    Hong, Seong-Cheol ; Hong, James Won-Ki ; Ju, Hongtaek

  • Author_Institution
    Dept. of Comput. Sci. & Eng., POSTECH, Pohang, South Korea
  • fYear
    2011
  • fDate
    21-23 Sept. 2011
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    IP prefix hijacking is a well-known security threat that corrupts Internet routing tables and has some common characteristics such as MOAS conflicts and invalid routes in BGP messages. We propose a simple but effective IP prefix hijacking detection method which is based on reachability monitoring. Network reachability means a characteristic that a packet must reach the destination network although the network path is changed due to routing instability. However, when IP prefix hijacking occurs, the traffic sent to victim network does not reach the intended destination but is delivered to attacker network. By identifying the characteristics of the destination network such as network fingerprints, we can know whether the traffic reach the correct destination. In this paper, we present the method of collecting network fingerprints for verifying destination reachability and also propose an IP prefix hijacking detection method using the collected fingerprints. The IP prefix hijacking detection method based on network reachability is effective and useful, which uses a simple active probing and denotes a present network condition.
  • Keywords
    IP networks; Internet; computer network security; internetworking; reachability analysis; routing protocols; telecommunication traffic; AS characteristics; BGP messages; IP prefix hijacking detection method; Internet routing tables; autonomous system; border gateway protocol; destination network; destination reachability verification; network fingerprints; network reachability; network traffic; reachability monitoring; routing instability; security threat; Fingerprint recognition; IP networks; Internet; Monitoring; Routing; Security; Servers; BGP Security; Fingerprinting; IP Prefix Hijacking;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium (APNOMS), 2011 13th Asia-Pacific
  • Conference_Location
    Taipei
  • Print_ISBN
    978-1-4577-1668-3
  • Type

    conf

  • DOI
    10.1109/APNOMS.2011.6077014
  • Filename
    6077014