A method and system for detecting prefix hijacking for uncertain information sources

By building a prefix cloud droplet and a dictionary tree combined with a dual-factor verification mechanism, the problem of insufficient real-time and accuracy in BGP exception detection is solved, and efficient and accurate prefix hijacking detection and traceability of the BGP network is achieved.

CN120415896BActive Publication Date: 2025-08-26NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510863681.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-08-26
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

The existing BGP anomaly detection methods cannot meet the requirements of real-time and accuracy at the same time, and face timely degeneration of data uncertainty and incompleteness. The BGP network is huge, making it difficult to explain the detection results and frequent false alarms and missed reports.

Method used

The prefix hijacking detection method based on cloud model theory is adopted, and the prefix cloud droplets are constructed, combined with dictionary tree and dual-factor verification mechanism, space-time stability analysis and online detection are performed, and the Trie tree structure is used for efficient storage and retrieval, so as to achieve accurate detection of uncertain sources.

Benefits of technology

Real-time online detection and traceability of BGP prefix hijacking is realized, the accuracy and interpretability of detection are improved, the false positive rate is reduced, and the dynamic changes and complexity of the BGP network are adapted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415896B_ABST
    Figure CN120415896B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for detecting prefix hijacking for uncertain sources. The method comprises: obtaining data from the routing information base, resource public key infrastructure, and Internet routing registry in the Border Gateway Protocol; constructing prefix cloud droplets from the time, space, and data source dimensions based on cloud model theory, and deriving deterministic data and uncertain data based on the discreteness of the cloud model; performing spatiotemporal stability analysis on the deterministic data, dynamically scoring each prefix cloud droplet, and establishing a dynamic deterministic information base; for the uncertain data, performing online route detection using a custom dictionary tree; utilizing prefix coverage and matching rules in combination with a dual verification mechanism to determine whether the route is legitimate, thereby completing anomaly detection and online updating. The present invention proposes a prefix hijacking detection method based on cloud model theory and a Trie tree to overcome the characteristics of the Border Gateway Protocol, such as dynamic changes, complex and large-scale networks, and uncertain data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of inter-domain anomaly detection in inter-domain routing security, and more specifically, relates to a prefix hijacking detection method and system for uncertain information sources. Background Art

[0002] The Border Gateway Protocol (BGP), as a core Internet routing protocol, provides a fundamental foundation for interconnecting autonomous systems worldwide. However, its initial design lacked a security authentication mechanism, leading to frequent BGP anomalies. Prefix hijacking incidents, in particular, have occurred with increasing frequency and widespread impact in recent years, posing a significant threat to global inter-domain routing security.

[0003] BGP anomaly detection detects anomalies using actively and passively acquired routing data and further locates suspicious routing information (prefixes, ASes, etc.), enabling operations personnel to quickly trace and mitigate the anomaly. Existing BGP anomaly detection methods are primarily based on active detection, machine learning, and routing logic. Active detection methods detect connectivity between ASes through active traffic probing. However, as BGP topologies become increasingly complex, this leads to significant overhead, making full detection impossible and lacking real-time performance. Machine learning methods use algorithms to model network traffic or routing data to identify anomaly patterns, but rely on large amounts of labeled data. Model performance is affected by data quality and feature engineering, and the black-box effect of deep learning models makes detection results difficult to interpret. Routing logic methods detect prefix hijacking by analyzing BGP routing information, offering real-time and interpretable detection capabilities. However, they rely heavily on data reliability and are prone to false positives or false negatives when faced with inaccurate or incomplete data.

[0004] Existing methods cannot simultaneously meet the requirements of real-time and accuracy, facing the following challenges: the uncertainty, incompleteness, and time-varying nature of collected data; the dynamic nature of BGP routing behavior; and the large scale of distributed BGP networks. Therefore, research on more effective BGP anomaly detection and tracing mechanisms is needed to ensure national inter-domain network security. Summary of the Invention

[0005] In view of the technical problems existing in the prior art, the present invention provides a prefix hijacking detection method and system for uncertain information sources, so as to overcome the characteristics of BGP dynamic changes, complex and large-scale networks, and data uncertainty.

[0006] According to a first aspect of the present invention, a method for detecting prefix hijacking for an uncertain source is provided, comprising the following steps:

[0007] S1. Obtaining the routing information base, resource public key infrastructure, and Internet routing registry data in the Border Gateway Protocol;

[0008] S2. Build a cloud model. Based on the cloud model theory, construct prefix cloud droplets from the dimensions of time, space, and data source. Divide the data into deterministic data and uncertain data based on the discrete degree of the cloud model.

[0009] S3. Perform spatiotemporal stability analysis on deterministic data, dynamically score each prefix cloud droplet, and establish a dynamic deterministic information database;

[0010] S4. For uncertain data, use a custom dictionary tree to perform online route detection; the dictionary tree includes an online prefix tree and an offline prefix tree. The online prefix tree stores and evaluates the certainty of all prefixes and their origin autonomous systems; the offline prefix tree stores the mapping relationship between verified legal prefixes and autonomous systems;

[0011] S5. Use prefix coverage and matching rules, combined with a double verification mechanism, to determine whether the route is legal, thereby completing anomaly detection and online updates.

[0012] On the basis of the above technical solution, the present invention can also make the following improvements.

[0013] Optionally, obtaining the routing information base, resource public key infrastructure, and Internet routing registration center data in the border gateway protocol includes:

[0014] Collect routing information base, resource public key infrastructure and Internet routing registration center data related to the Border Gateway Protocol, extract the prefix, source AS number, time and source information from the collected three-party database, and insert the collected three-party database into the IP prefix tree.

[0015] Optionally, the building of the cloud model includes:

[0016] The expected value, entropy and super entropy extracted from prefix cloud droplets are used to construct a cloud model of prefix cloud droplets. The three characteristics are time persistence, spatial consistency and data source. The expected value, entropy and super entropy are weighted to calculate the uncertainty of cloud droplets.

[0017] Optionally, prefix cloud droplets are constructed from the time dimension based on cloud model theory, including:

[0018] Calculating the characteristic components of temporal persistence involves defining an observation matrix and calculating the duration of prefix cloud droplets using the temporal persistence vector. The more recent the appearance of a prefix cloud droplet, the higher its credibility. The temporal persistence of a prefix cloud droplet is calculated as follows:

[0019]

[0020] in, Temporal persistence, which indicates the degree of temporal persistence of the autonomous system’s continuous announcement of prefix cloud droplets; It is represented as a persistence vector, and d represents the size of the time window; Represents the weight coefficient of time in the observation window.

[0021] Optionally, prefix cloud droplets are constructed from the spatial dimension based on cloud model theory, including:

[0022] The number of times a prefix cloud droplet is observed by the observation point is calculated using the spatial consistency vector. The more times a prefix cloud droplet is observed, the more stable it is in space. The calculation method for the number of times a prefix cloud droplet is observed by the observation point is as follows:

[0023]

[0024] in, is the spatial consistency, which indicates the number of times the prefix cloud droplet pair is observed at the observation point; It is represented by the number of times the prefix cloud droplet is observed by the observation point, and d represents the size of the time window; is a weight vector, which indicates the reliability of the observation point.

[0025] Optionally, prefix cloud droplets are constructed from the data source dimension based on cloud model theory, including:

[0026] Calculating the characteristic components of the membership attributes includes: using the membership vector to represent the ownership of the prefix cloud droplets whose information is extracted from different data sources; the characteristic components of the membership attributes are calculated as follows:

[0027]

[0028] in, Data source, which represents the prefix cloud droplet of information extracted from different data sources; represents the membership vector; is a weight vector, which indicates the reliability of the data.

[0029] Optionally, the discrete degree of the cloud model is divided into deterministic data and uncertain data, including:

[0030] In the cloud model, a multidimensional cloud model is constructed using temporal persistence, spatial consistency, and affiliation. The reliability of prefix cloud droplets is calculated using the cloud droplet certainty. The calculation formula is:

[0031]

[0032] Where y represents the characteristic vector of a prefix cloud droplet The degree of certainty of belonging to the feature cloud, They are characteristic cloud droplets belonging to the three characteristic components representing temporal persistence, spatial consistency, and membership; For interval Random values ​​of the normal function generated on , and The same calculation method is used for both; They represent the expected values ​​of the three characteristic components of temporal persistence, spatial consistency, and membership respectively.

[0033] Optionally, performing spatiotemporal stability analysis on deterministic data, dynamically scoring each prefix cloud droplet, and establishing a dynamic deterministic information database includes:

[0034] S31. Define the prefix cloud droplet characteristic cloud and use the cloud model to express the qualitative concept of prefix cloud droplet stability. Several cloud droplets are represented as , where the three elements of the vector s i t 、s i s 、s i m Represent cloud droplets the temporal persistence, spatial consistency, and affiliation characteristics of the

[0035] S32. Calculate cloud model parameters, and calculate the expectation, entropy, and super entropy of the prefix cloud droplet characteristic cloud; the expectation is a typical sample value quantified by a qualitative concept, the entropy measures the degree of dispersion of all cloud droplets, and the super entropy is used to measure the uncertainty of entropy;

[0036] S33. Calculate the uncertainty of the prefix cloud droplets, and calculate the reliability of the prefix cloud droplets based on the cloud droplet membership.

[0037] Optionally, for uncertain data, using a custom dictionary tree to perform online detection on routes includes:

[0038] S41. Using prefix coverage and matching rules, evaluate the relationship between the incoming route and the legal prefix stored in the offline prefix tree, verify whether the uncertain data is a legal prefix, and determine whether the prefix matches a legal autonomous system number (ASN).

[0039] S42. In a dynamic network environment, when the newly added prefix cloud drop exceeds a threshold, the offline prefix tree is updated according to the IP prefix tree IPTrie.

[0040] According to a second aspect of the present invention, a prefix hijacking detection system for an uncertain source is provided, comprising:

[0041] A data collection module for obtaining routing information base, resource public key infrastructure and Internet routing registry data in the Border Gateway Protocol;

[0042] The data confidence calculation module is used to build a cloud model. Based on cloud model theory, prefix cloud droplets are constructed from the dimensions of time, space, and data source. Data is divided into deterministic data and uncertain data based on the degree of discreteness of the cloud model. For deterministic data, spatiotemporal stability analysis is performed, each prefix cloud droplet is dynamically scored, and a dynamic deterministic information library is established. For uncertain data, a custom dictionary tree is used to perform online routing detection. The dictionary tree includes an online prefix tree and an offline prefix tree. The online prefix tree stores and evaluates the certainty of all prefixes and their origin autonomous systems. The offline prefix tree stores the mapping relationship between verified legal prefixes and autonomous systems.

[0043] The anomaly detection and location module is used to use prefix coverage and matching rules, combined with a double verification mechanism, to determine whether the route is legal, thereby completing anomaly detection and online updates.

[0044] Technical effects and advantages of the present invention:

[0045] The present invention provides a prefix hijacking detection method and system for uncertain sources. By comprehensively measuring the relevant routing data of the Border Gateway Protocol and comprehensively considering the inconsistency, time-varying and multi-origin characteristics of the data, a more accurate data basis is provided for subsequent detection. The online routing credibility evaluation model designed based on the cloud model theory integrates the three dimensions of time, space and data source, effectively extracts the mapping relationship between time and space stability, converts uncertain data into deterministic data, and improves the accuracy of detection. The Trie tree structure is used to efficiently store and retrieve prefix and ASN information. Combined with a double verification mechanism, it can quickly and accurately detect prefix hijacking behavior, realize real-time online detection and traceability, and the detection results have good interpretability. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 A flowchart of a method for detecting prefix hijacking for uncertain information sources provided by an embodiment of the present invention;

[0047] Figure 2 A schematic diagram of characteristic cloud droplet distribution of a cloud model provided by an embodiment of the present invention;

[0048] Figure 3 A diagram of the construction and detection speed of a Trie tree under different prefix lengths provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0049] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0050] It is understandable that, based on the defects in the background technology, the embodiment of the present invention proposes a prefix hijacking detection method for uncertain sources, specifically as follows: Figure 1 As shown, the following steps are included:

[0051] S1. Obtaining the routing information base, resource public key infrastructure, and Internet routing registry data in the Border Gateway Protocol;

[0052] It's important to note that the Border Gateway Protocol (BGP) is an exterior gateway protocol used to exchange routing information between different networks. It runs on the border routers of Internet service providers (ISPs), enterprise networks, and other large networks, helping these networks connect to each other and enable data communication.

[0053] In computer networks, routing tables are aptly referred to as Routing Information Bases (RIBs). Each router maintains a global routing table, which can be viewed using the display iprouting-table command. Furthermore, each routing protocol running on a router maintains its own routing table. These routing tables, along with the global routing table, constitute the router's complete RIB.

[0054] Resource Public Key Infrastructure (RPKI), also known as Resource Certification, is a public key infrastructure (PKI) framework designed to make the Internet routing infrastructure more secure.

[0055] The Internet Routing Registry (IRR) contains information about autonomous system numbers and routing prefix number prefixes submitted and maintained by Internet service providers or other entities.

[0056] After obtaining the Routing Information Base (RIB), Resource Public Key Infrastructure (RPKI), and Internet Routing Registry (IRR) data from the Border Gateway Protocol, the process also includes pre-processing the data. This includes collecting RIB, RPKI, and IRR data related to the BGP, extracting prefixes, source AS numbers, time, and source information from the collected RIB databases, and then inserting the collected RI databases into the IP prefix tree.

[0057] It's important to note that an AS number (Autonomous System Number) is a unique identifier used to identify an autonomous system (AS) on the Internet. An autonomous system is a group of networks under the control of the same organization or administrative entity that share the same routing policies and protocols, forming a single administrative unit. An AS number is a 32-bit numeric identifier used for routing and path transmission between autonomous systems.

[0058] S2. Build a cloud model. Based on the cloud model theory, construct prefix cloud droplets from the dimensions of time, space, and data source. Based on the discreteness of the cloud model, the data is divided into deterministic data and uncertain data.

[0059] It's important to note that the cloud model uses three numerical characteristics of computational data: expected value (Ex), entropy (En), and excess entropy (He) to convert uncertainty between qualitative concepts and quantitative descriptions. Prefix cloud droplets are constructed from the dimensions of time, space, and data source, and deterministic and uncertain data are derived based on the cloud model's degree of discreteness. Figure 2 Schematic diagram of the characteristic cloud droplet distribution of the cloud model provided by an embodiment of the present invention; each cloud droplet in the figure corresponds to the spatiotemporal characteristics of a prefix cloud droplet, and the depth of its color indicates the degree of uncertainty of the cloud droplet.

[0060] Building a cloud model involves extracting the expected value (Ex), entropy (En), and excess entropy (He) of the prefix cloud droplet to construct a cloud model for the prefix cloud droplet. The three characteristics are temporal persistence, spatial consistency, and data source. These three characteristics are weighted to calculate the uncertainty of the cloud droplet. The specific steps are as follows.

[0061] The prefix cloud droplets constructed based on the cloud model theory from the time, space and data source dimensions are:

[0062] S21. Calculate the characteristic components of time duration, including: defining the observation matrix U , through the time persistence vector Calculate the duration of the prefix cloud droplet announcement using the weight vector The weight coefficient of the time in the observation window is expressed. The newer the time of the prefix cloud droplet, the higher the credibility. The calculation method of the time persistence of the prefix cloud droplet is as follows:

[0063]

[0064] in, Temporal persistence, which indicates the degree of temporal persistence of the autonomous system’s continuous announcement of prefix cloud droplets; It is represented as a persistence vector, and d represents the size of the time window; Represents the weight coefficient of time in the observation window.

[0065] In order to facilitate the quantitative calculation of features, we define the observation matrix , the observation matrix is ​​expressed as:

[0066]

[0067] in, It means that if observation point j observes prefix i, the value is 1, otherwise the value is 0; c represents the number of observation points, and d represents the length of the observation window.

[0068] S22, calculating the characteristic components of spatial consistency, including: using the spatial consistency vector Calculate the number of times the prefix cloud droplet is observed by the observation point, the weight vector Indicates the reliability of the observation point. The more times it is observed, the more stable the prefix cloud droplet is in space. The calculation method for the number of times the prefix cloud droplet is observed by the observation point is as follows:

[0069]

[0070] in, is the spatial consistency, which indicates the number of times the prefix cloud droplet pair is observed at the observation point; It is represented by the number of times the prefix cloud droplet is observed by the observation point, and d represents the size of the time window; is a weight vector, which indicates the reliability of the observation point.

[0071] S23, calculating the characteristic component of the membership, including: using the membership vector to represent the ownership of the prefix cloud droplet whose extracted information comes from different data sources; the characteristic component of the membership is calculated as follows:

[0072]

[0073] in, Data source, which represents the prefix cloud droplet of information extracted from different data sources; represents the membership vector, is a weight vector, which indicates the reliability of the data and adopts a linear decreasing function calculate.

[0074] Finally, the discrete degree of the cloud model is divided into deterministic data and uncertain data; including:

[0075] In the cloud model, a multidimensional cloud model is constructed using temporal persistence, spatial consistency, and affiliation. The reliability of prefix cloud droplets is calculated using the cloud droplet certainty. The calculation formula is:

[0076]

[0077] Where y represents the characteristic vector of a prefix cloud droplet The degree of certainty of belonging to the feature cloud, They are characteristic cloud droplets belonging to the three characteristic components representing temporal persistence, spatial consistency, and membership; For interval Random values ​​of the normal function generated on , and The same calculation method is used for both; They represent the expected values ​​of the three characteristic components of temporal persistence, spatial consistency, and membership respectively.

[0078] S3. Perform spatiotemporal stability analysis on deterministic data, dynamically score each prefix cloud droplet, and establish a dynamic deterministic information database;

[0079] In this embodiment, drawing on the cloud model concept, the inverse cloud transformation algorithm is used to achieve bidirectional changes in qualitative concepts and quantitative values. Specifically, the characteristics of each prefix cloud droplet are scored and a dynamic deterministic information database is established. The steps are as follows:

[0080] S31. Define the prefix cloud droplet characteristic cloud and use the cloud model to express the qualitative concept of prefix cloud droplet stability. Several cloud droplets are represented as , where the three elements of the vector s i t 、s i s 、s i m Represent cloud droplets the temporal persistence, spatial consistency, and affiliation characteristics of the

[0081] S32. Calculate the cloud model parameters and the expectation, entropy, and super entropy of the prefix cloud droplet characteristic cloud; expectation is the most typical sample value for the quantification of qualitative concepts, entropy measures the degree of dispersion of all cloud droplets, and super entropy measures the uncertainty of entropy.

[0082] The eigenvector is represented as

[0083] Among them, expectation Ex is the most typical sample value for the quantification of qualitative concepts; entropy En is determined by the randomness and fuzziness of qualitative concepts, and is used to measure the discrete degree of all cloud droplets, and can also reflect the range of cloud droplet values ​​accepted by the concept; excess entropy He is used to measure the uncertainty of entropy and is a description of the association between fuzziness and randomness.

[0084] S33. Calculate the uncertainty of the prefix cloud droplet and calculate the reliability of the prefix cloud droplet based on the cloud droplet membership. In this embodiment, a multidimensional cloud model is constructed using temporal persistence, spatial consistency, and membership, and the reliability of the prefix cloud droplet is calculated using the cloud droplet certainty.

[0085] S4. For uncertain data, use a custom dictionary tree to perform online detection on the route;

[0086] The dictionary tree includes an online prefix tree and an offline prefix tree, wherein the online prefix tree stores and evaluates the certainty of all prefixes and their origin autonomous systems, and the offline prefix tree stores the mapping relationship between verified legal prefixes and autonomous systems; Figure 3 This figure shows the construction and detection speed of the dictionary tree for different prefix lengths provided by an embodiment of the present invention. As can be seen from the figure, the construction time and search time of the dictionary tree are relatively small as the prefix length changes, indicating that real-time anomaly detection can be performed under different prefix lengths.

[0087] In this embodiment, the uncertainty of the prefix cloud droplet is defined as The prefix cloud droplets whose calculated probability exceeds a certain threshold are screened out from the mapping relationship library, and the new feature vectors that do not exceed the threshold are added to update and adjust the feature cloud.

[0088] For uncertain data, online detection of routes using a custom dictionary tree includes:

[0089] S41. Using prefix coverage and matching rules, evaluate the relationship between the incoming route and the legal prefix stored in the offline prefix tree, verify whether it is a legal prefix, and determine whether the prefix matches a legal autonomous system number (ASN).

[0090] S42. In a dynamic network environment, when the number of newly added prefix cloud drops exceeds a certain threshold, the offline prefix tree is updated based on the IP prefix tree (IPTrie), achieving automated updates. The online and offline prefix trees work together to continuously verify and update the legitimacy of prefixes, improving the real-time and accuracy of detection and enhancing the ability to handle uncertain sources.

[0091] S5. Use prefix coverage and matching rules, combined with a double verification mechanism, to determine whether the route is legal, thereby completing anomaly detection and online updates.

[0092] The aforementioned dual verification mechanism, utilizing prefix coverage and matching rules, determines whether a route is legitimate: a prefix is ​​considered legitimate only if it matches a known legitimate route (via coverage and matching criteria). If a prefix does not meet any valid routing rules (i.e., is covered or does not match), it is considered invalid.

[0093] To test the effectiveness of CloudTrie in detecting prefix hijacking, this embodiment of the present invention uses a multi-source dataset, including RPKI, IRR, and RIB tables. The dataset covers all BGP updates from January 2023 and is divided into six time windows, each containing five consecutive days of data. The case studies in the experiment are analyzed using routing data from the corresponding time periods and verified using authoritative news reports.

[0094] The experimental environment was an AMD EPYC 7K62 processor with 48 cores. The code ran on the Linux operating system with 64GB of memory and was implemented in Python. Detection accuracy and time were used as performance evaluation metrics.

[0095] Experimental results demonstrate that approximately 85% of prefix cloud droplets have an uncertainty less than 0.4, indicating that most routing information has a high degree of credibility. The cloud model effectively adapts to the dynamic nature of BGP routing. The Trie tree is an efficient data structure for storing and retrieving IP prefixes, maintaining high query efficiency while consuming less memory. The proposed method reduces the false positive rate to 9.3% while maintaining 85.7% detection coverage (comparable to Artemis), an average reduction of 10.6 percentage points compared to the baseline method. Case studies demonstrate the successful detection of a historical hijacking incident, demonstrating its effectiveness in practical applications.

[0096] It can be seen from the above experimental results that the prefix hijacking detection method CloudTrie based on cloud model theory and Trie tree proposed in the embodiment of the present invention can more accurately detect BGP prefix hijacking and perform source tracing analysis.

[0097] According to a second aspect of the present invention, an embodiment of the present invention further provides a prefix hijacking detection system for an uncertain source, which is used in the above-mentioned prefix hijacking detection method for an uncertain source, and the system includes:

[0098] A data collection module for obtaining routing information base, resource public key infrastructure and Internet routing registry data in the Border Gateway Protocol;

[0099] The data confidence calculation module is used to build a cloud model. Based on cloud model theory, prefix cloud droplets are constructed from the dimensions of time, space, and data source. Data is divided into deterministic data and uncertain data based on the degree of discreteness of the cloud model. For deterministic data, spatiotemporal stability analysis is performed, each prefix cloud droplet is dynamically scored, and a dynamic deterministic information library is established. For uncertain data, a custom dictionary tree is used to perform online routing detection. The dictionary tree includes an online prefix tree and an offline prefix tree. The online prefix tree stores and evaluates the certainty of all prefixes and their origin autonomous systems. The offline prefix tree stores the mapping relationship between verified legal prefixes and autonomous systems.

[0100] The anomaly detection and location module is used to use prefix coverage and matching rules, combined with a double verification mechanism, to determine whether the route is legal, thereby completing anomaly detection and online updates.

[0101] It can be understood that the prefix hijacking detection system for uncertain sources provided by the present invention corresponds to the prefix hijacking detection method for uncertain sources provided in the aforementioned embodiments. The relevant technical features of a prefix hijacking detection system for uncertain sources can refer to the relevant technical features of a prefix hijacking detection method for uncertain sources, which will not be repeated here.

[0102] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0103] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0104] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

[0105] Finally, it should be noted that the above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for detecting prefix hijacking for uncertain information sources, characterized in that: The following steps are involved: S1. Obtaining Routing Information Base (RIB), Resource Public Key Infrastructure (RPKI), and Internet Routing Registry (IRR) data in the Border Gateway Protocol; including: collecting RIB, RPKI, and IRR data related to the Border Gateway Protocol, extracting prefixes, source AS numbers, time, and source information from the collected three-party databases, and inserting the collected three-party databases into the IP prefix tree; S2. Build a cloud model. Based on cloud model theory, prefix cloud droplets are constructed from the dimensions of time, space, and data source. Data is divided into deterministic data and uncertain data based on the degree of discreteness of the cloud model. Specifically, the prefix cloud droplet constructed from the time dimension based on cloud model theory includes: Calculating the characteristic components of temporal persistence involves defining an observation matrix and calculating the duration of prefix cloud droplets using the temporal persistence vector. The more recent the prefix cloud droplet appears, the higher its credibility. The temporal persistence of the prefix cloud droplets is calculated as follows: in, Temporal persistence, which indicates the degree of temporal persistence of the autonomous system’s continuous announcement of prefix cloud droplets; It is represented as a persistence vector, and d represents the size of the time window; Represents the weight coefficient of time in the observation window; Based on cloud model theory, prefix cloud droplets are constructed from the spatial dimension, including: The number of times a prefix cloud droplet is observed by the observation point is calculated using the spatial consistency vector. The more times a prefix cloud droplet is observed, the more stable it is in space. The calculation method for the number of times a prefix cloud droplet is observed by the observation point is as follows: in, is the spatial consistency, which indicates the number of times the prefix cloud droplet pair is observed at the observation point; It is represented by the number of times the prefix cloud droplet is observed by the observation point, and d represents the size of the time window; is a weight vector, indicating the reliability of the observation point; Based on the cloud model theory, prefix cloud droplets are constructed from the data source dimension, including: Calculating the characteristic components of the membership attributes includes: using the membership vector to represent the ownership of the prefix cloud droplets whose information is extracted from different data sources; the characteristic components of the membership attributes are calculated as follows: in, Data source, which represents the prefix cloud droplet of information extracted from different data sources; represents the membership vector; is a weight vector, indicating the reliability of the data; S3. Perform spatiotemporal stability analysis on deterministic data, dynamically score each prefix cloud droplet, and establish a dynamic deterministic information database; S4. For uncertain data, use a custom dictionary tree to perform online route detection; the dictionary tree includes an online prefix tree and an offline prefix tree. The online prefix tree stores and evaluates the certainty of all prefixes and their origin autonomous systems; the offline prefix tree stores the mapping relationship between verified legal prefixes and autonomous systems; S5. Use prefix coverage and matching rules, combined with a double verification mechanism, to determine whether the route is legal, thereby completing anomaly detection and online updates.

2. The method for detecting prefix hijacking for uncertain information sources according to claim 1, wherein: The cloud model construction includes: The expected value, entropy and super entropy extracted from prefix cloud droplets are used to construct a cloud model of prefix cloud droplets. The three characteristics are time persistence, spatial consistency and data source. The expected value, entropy and super entropy are weighted to calculate the uncertainty of cloud droplets.

3. The method for detecting prefix hijacking for uncertain information sources according to claim 1, wherein: The discrete degree of the cloud model is divided into deterministic data and uncertain data, including: In the cloud model, a multidimensional cloud model is constructed using temporal persistence, spatial consistency, and affiliation. The reliability of prefix cloud droplets is calculated using the cloud droplet certainty. The calculation formula is: Where y represents the characteristic vector of a prefix cloud droplet The degree of certainty of belonging to the feature cloud, They are characteristic cloud droplets belonging to the three characteristic components representing temporal persistence, spatial consistency, and membership; For interval Random values ​​of the normal function generated on , and The same calculation method is used for both; They represent the expected values ​​of the three characteristic components of temporal persistence, spatial consistency, and membership respectively.

4. The method for detecting prefix hijacking for uncertain information sources according to claim 1, wherein: The above-mentioned spatiotemporal stability analysis of deterministic data, dynamic scoring of each prefix cloud droplet, and establishment of a dynamic deterministic information database include: S31. Define the prefix cloud droplet characteristic cloud and use the cloud model to express the qualitative concept of prefix cloud droplet stability. Several cloud droplets are represented as , where the three elements of the vector s i t 、s i s 、s i m Represent cloud droplets the temporal persistence, spatial consistency, and affiliation characteristics of the S32. Calculate cloud model parameters, and calculate the expectation, entropy, and super entropy of the prefix cloud droplet characteristic cloud; the expectation is a typical sample value quantified by a qualitative concept, the entropy measures the degree of dispersion of all cloud droplets, and the super entropy is used to measure the uncertainty of entropy; S33. Calculate the uncertainty of the prefix cloud droplets, and calculate the reliability of the prefix cloud droplets based on the cloud droplet membership.

5. The method for detecting prefix hijacking for uncertain information sources according to claim 1, wherein: For uncertain data, online detection of routes using a custom dictionary tree includes: S41. Using prefix coverage and matching rules, evaluate the relationship between the incoming route and the legal prefix stored in the offline prefix tree, verify whether the uncertainty data is a legal prefix, and determine whether the prefix matches a legal autonomous system number. S42. In a dynamic network environment, when the newly added prefix cloud drop exceeds a threshold, the offline prefix tree is updated according to the IP prefix tree IPTrie.

6. A prefix hijacking detection system for uncertain information sources, used in a prefix hijacking detection method for uncertain information sources according to any one of claims 1 to 5, characterized in that: The system comprises: The data collection module is used to obtain the routing information base, resource public key infrastructure and Internet routing registration center data in the border gateway protocol; including: collecting the routing information base, resource public key infrastructure and Internet routing registration center data related to the border gateway protocol, extracting the prefix, source AS number, time and source information from the collected three-party database, and inserting the collected three-party database into the IP prefix tree; The data confidence calculation module is used to build a cloud model. Based on cloud model theory, prefix cloud droplets are constructed from the time, space, and data source dimensions. Data is divided into deterministic data and uncertain data based on the degree of discreteness of the cloud model. For deterministic data, spatiotemporal stability analysis is performed, each prefix cloud droplet is dynamically scored, and a dynamic deterministic information library is established. For uncertain data, a custom dictionary tree is used to perform online routing detection. The dictionary tree includes an online prefix tree and an offline prefix tree. The online prefix tree stores and evaluates the certainty of all prefixes and their origin autonomous systems. The offline prefix tree stores the mapping relationship between verified legal prefixes and autonomous systems. Specifically, constructing prefix cloud droplets from the time dimension based on cloud model theory includes: Calculating the characteristic components of temporal persistence involves defining an observation matrix and calculating the duration of prefix cloud droplets using the temporal persistence vector. The more recent the prefix cloud droplet appears, the higher its credibility. The temporal persistence of the prefix cloud droplets is calculated as follows: in, Temporal persistence, which indicates the degree of temporal persistence of the autonomous system’s continuous announcement of prefix cloud droplets; It is represented as a persistence vector, and d represents the size of the time window; Represents the weight coefficient of time in the observation window; Based on cloud model theory, prefix cloud droplets are constructed from the spatial dimension, including: The number of times a prefix cloud droplet is observed by the observation point is calculated using the spatial consistency vector. The more times a prefix cloud droplet is observed, the more stable it is in space. The calculation method for the number of times a prefix cloud droplet is observed by the observation point is as follows: in, is the spatial consistency, which indicates the number of times the prefix cloud droplet pair is observed at the observation point; It is represented by the number of times the prefix cloud droplet is observed by the observation point, and d represents the size of the time window; is a weight vector, indicating the reliability of the observation point; Based on the cloud model theory, prefix cloud droplets are constructed from the data source dimension, including: Calculating the characteristic components of the membership attributes includes: using the membership vector to represent the ownership of the prefix cloud droplets whose information is extracted from different data sources; the characteristic components of the membership attributes are calculated as follows: in, Data source, which represents the prefix cloud droplet of information extracted from different data sources; represents the membership vector; is a weight vector, indicating the reliability of the data; The anomaly detection and location module is used to use prefix coverage and matching rules, combined with a double verification mechanism, to determine whether the route is legal, thereby completing anomaly detection and online updates.

Citation Information

Patent Citations

  • Coordinated monitoring method for preventing BGP routing hijacking

    CN102394794A

  • Inter-network routing hijacking detection method based on multiple filtering and electronic equipment

    CN113328990A