Title :
IP prefix hijacking detection using the collection of as characteristics
Author :
Hong, Seong-Cheol ; Hong, James Won-Ki ; Ju, Hongtaek
Author_Institution :
Dept. of Comput. Sci. & Eng., POSTECH, Pohang, South Korea
Abstract :
IP prefix hijacking is a well-known security threat that corrupts Internet routing tables and has some common characteristics such as MOAS conflicts and invalid routes in BGP messages. We propose a simple but effective IP prefix hijacking detection method which is based on reachability monitoring. Network reachability means a characteristic that a packet must reach the destination network although the network path is changed due to routing instability. However, when IP prefix hijacking occurs, the traffic sent to victim network does not reach the intended destination but is delivered to attacker network. By identifying the characteristics of the destination network such as network fingerprints, we can know whether the traffic reach the correct destination. In this paper, we present the method of collecting network fingerprints for verifying destination reachability and also propose an IP prefix hijacking detection method using the collected fingerprints. The IP prefix hijacking detection method based on network reachability is effective and useful, which uses a simple active probing and denotes a present network condition.
Keywords :
IP networks; Internet; computer network security; internetworking; reachability analysis; routing protocols; telecommunication traffic; AS characteristics; BGP messages; IP prefix hijacking detection method; Internet routing tables; autonomous system; border gateway protocol; destination network; destination reachability verification; network fingerprints; network reachability; network traffic; reachability monitoring; routing instability; security threat; Fingerprint recognition; IP networks; Internet; Monitoring; Routing; Security; Servers; BGP Security; Fingerprinting; IP Prefix Hijacking;
Conference_Titel :
Network Operations and Management Symposium (APNOMS), 2011 13th Asia-Pacific
Conference_Location :
Taipei
Print_ISBN :
978-1-4577-1668-3
DOI :
10.1109/APNOMS.2011.6077014