BGPfuse: using visual feature fusion for the detection and attribution of BGP anomalies

BGPfuse: using visual feature fusion for the detection and attribution of BGP anomalies
复制标题

BGPfuse:使用视觉特征融合来检测和归因 BGP 异常

DOI:
--
复制
发表时间:
2013
期刊:
Visualization for Computer Security
影响因子:
--
通讯作者:
D. Tzovaras
D. Tzovaras
中科院分区:
--
文献类型:
--
作者:
Stavros Papadopoulos;G. Theodoridis;D. Tzovaras

文献摘要

被引文献

相似文献

本文提出了一种用于可视化和探索BGP(边界网关协议)路径变化异常的方案BGPfuse。BGPfuse使用一组BGP特征,能够量化每个路径改变事件的异常程度。此外,还引入了可视化方法来实现这些多特征的有效融合。利用人类的感知,可以克服现有的基于权重的融合方法的静态特性。使用平行坐标方法对这些特征进行可视化,并进一步增强了过滤功能,从而区分正常和异常事件。BGPfuse使用多个链接的图视图来深入表示所涉及的自治系统(as)之间的关系,以及一个组合图视图来突出所有单个特征图之间的结构相似性。BGPfuse提供的结构相似性和过滤功能使分析人员能够对BGP特征进行视觉融合,从而发现任何可疑行为,并只关注最有趣的情况。BGPfuse的实验演示,通过果断捕获恶意BGP劫持事件,显示了所提出方法的分析潜力。
This paper presents BGPfuse, a scheme for visualizing and exploring BGP (Border Gateway Protocol) path change anomalies. BGPfuse uses a set of BGP features that are capable of quantifying the degree of anomaly of each path change event. Moreover, visual methods are introduced for performing the efficient fusion of these multiple features. The exploitation of the human perception, allows to overcome the static-nature of the existing weight-based fusion approaches. A Parallel Coordinates approach is used to visualize these features, which is further enhanced with filtering capabilities, so as to discriminate between normal and abnormal events. BGPfuse uses multiple linked graph views so as to represent in depth the relationships among the involved Autonomous Systems (ASes), as well as a combined graph view to highlight structural similarities between all the individual feature graphs. The structural similarities as well as the filtering capabilities provided by BGPfuse, enable the analyst to perform visual fusion of the BGP features, so as to detect any suspicious behavior and focus only in the most interesting cases. Experimental demonstration of BGPfuse, shows the analytical potential of the proposed approach by decisively capturing malicious BGP hijacking events.