Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table

Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table
复制标题

分析 BGP 串行劫持者:捕获全局路由表中持续存在的不当行为

DOI:
10.1145/3355369.3355581
复制
发表时间:
2019
期刊:
Proceedings of the Internet Measurement Conference
影响因子:
--
通讯作者:
D. Clark
D. Clark
中科院分区:
--
文献类型:
--
作者:
Cecilia Testart;P. Richter;Alistair King;A. Dainotti;D. Clark

文献摘要

被引文献

相似文献

BGP劫持仍然是当今互联网中的一个严重问题,具有广泛的后果。虽然劫持检测系统是现成的,但它们通常依赖于先验前缀所有权信息,并且本质上是反应性的。在这项工作中,我们对BGP劫持活动采取了一个新的视角:我们引入并跟踪串行劫持者的长期路由行为,这些网络经常在数月甚至数年的时间内反复劫持地址块用于恶意目的。基于我们通过从网络运营商邮件列表中提取信息构建的地面实况数据集,我们阐明了串行劫持者的主要路由特征,以及它们与合法网络的不同之处。然后,我们提取可以捕获这些行为差异的特征,并训练机器学习模型来自动识别表现出类似于连环劫机者特征的自治系统(AS)。我们的分类器识别出在全球IPv4路由表中具有相似行为的ASes。我们对这些网络进行了分析和分类,发现了各种恶意活动,错误配置以及良性劫持活动的指标。我们的工作为识别和理解这类重要的网络迈出了坚实的第一步,这可以帮助网络运营商采取积极措施来保护自己免受前缀劫持,并作为当前和未来检测系统的输入。
BGP hijacks remain an acute problem in today's Internet, with widespread consequences. While hijack detection systems are readily available, they typically rely on a priori prefix-ownership information and are reactive in nature. In this work, we take on a new perspective on BGP hijacking activity: we introduce and track the long-term routing behavior of serial hijackers, networks that repeatedly hijack address blocks for malicious purposes, often over the course of many months or even years. Based on a ground truth dataset that we construct by extracting information from network operator mailing lists, we illuminate the dominant routing characteristics of serial hijackers, and how they differ from legitimate networks. We then distill features that can capture these behavioral differences and train a machine learning model to automatically identify Autonomous Systems (ASes) that exhibit characteristics similar to serial hijackers. Our classifier identifies ≈ 900 ASes with similar behavior in the global IPv4 routing table. We analyze and categorize these networks, finding a wide range of indicators of malicious activity, misconfiguration, as well as benign hijacking activity. Our work presents a solid first step towards identifying and understanding this important category of networks, which can aid network operators in taking proactive measures to defend themselves against prefix hijacking and serve as input for current and future detection systems.