DocumentCode
2306491
Title
IP prefix hijacking detection using the collection of as characteristics
Author
Hong, Seong-Cheol ; Hong, James Won-Ki ; Ju, Hongtaek
Author_Institution
Dept. of Comput. Sci. & Eng., POSTECH, Pohang, South Korea
fYear
2011
fDate
21-23 Sept. 2011
Firstpage
1
Lastpage
7
Abstract
IP prefix hijacking is a well-known security threat that corrupts Internet routing tables and has some common characteristics such as MOAS conflicts and invalid routes in BGP messages. We propose a simple but effective IP prefix hijacking detection method which is based on reachability monitoring. Network reachability means a characteristic that a packet must reach the destination network although the network path is changed due to routing instability. However, when IP prefix hijacking occurs, the traffic sent to victim network does not reach the intended destination but is delivered to attacker network. By identifying the characteristics of the destination network such as network fingerprints, we can know whether the traffic reach the correct destination. In this paper, we present the method of collecting network fingerprints for verifying destination reachability and also propose an IP prefix hijacking detection method using the collected fingerprints. The IP prefix hijacking detection method based on network reachability is effective and useful, which uses a simple active probing and denotes a present network condition.
Keywords
IP networks; Internet; computer network security; internetworking; reachability analysis; routing protocols; telecommunication traffic; AS characteristics; BGP messages; IP prefix hijacking detection method; Internet routing tables; autonomous system; border gateway protocol; destination network; destination reachability verification; network fingerprints; network reachability; network traffic; reachability monitoring; routing instability; security threat; Fingerprint recognition; IP networks; Internet; Monitoring; Routing; Security; Servers; BGP Security; Fingerprinting; IP Prefix Hijacking;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Operations and Management Symposium (APNOMS), 2011 13th Asia-Pacific
Conference_Location
Taipei
Print_ISBN
978-1-4577-1668-3
Type
conf
DOI
10.1109/APNOMS.2011.6077014
Filename
6077014
Link To Document