Routing origin authorization potential anomaly detection system based on routing state change analysis
Through the routing origin authorization potential anomaly detection system based on routing state change analysis, the classification task is used to solve the problem of difficult to identify the ROA issuance exception and distinguish the causes of invalid announcements in the prior art, and efficient detection and classification of ROA exceptions are achieved to prevent network interruptions and loss of legal traffic.
Patent Information
- Application Number
- CN202510461233.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art is difficult to effectively identify invalid declarations caused by ROA issuance exceptions, and it is impossible to accurately distinguish the causes of invalid declarations, and it is difficult to deal with challenges in real scenarios such as the short time of malicious declarations.
A route origin authorization potential anomaly detection system based on routing state change analysis is proposed. By collecting multi-source data, extracting and encoding multiple features, and using neural networks to perform classification tasks, the detection and classification of ROA anomalies are realized.
This system can effectively reduce the misjudgment of legal declarations caused by abnormal ROA, which is better than the existing state-of-the-art solutions, and can promptly detect ROA abnormalities that will lead to legal misjudgment, prevent network connection interruptions and loss of legal traffic.
Smart Images

Figure CN120200825A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer network technologies, and particularly to a routing origin authorization potential anomaly detection system based on routing status change analysis. Background Art
[0002] In today's digital age, the network has become a key infrastructure for the global economy and social life. The availability, stability, and security of the network are crucial for enterprises, government agencies, and individual users. Inter-domain routing is a key foundation for information flow in the Internet, responsible for guiding the transmission path of data globally. Thus, the security of inter-domain routing plays a crucial role in the field of network security. Attackers can often influence inter-domain routing through means such as route hijacking and path forgery, which may cause data traffic to be directed to untrusted destinations or disrupt the normal operation of network communication. In such cases, attackers can steal sensitive information, interrupt services, or carry out other malicious activities, seriously threatening network security and privacy. Therefore, ensuring the security of inter-domain routing has become the primary task of network management and security professionals.
[0003] Resource Public Key Infrastructure (RPKI) is a key technology for verifying the authenticity of Border Gateway Protocol (BGP) routing information. RPKI builds a trust chain of digital certificates, issues signed routing origin authorizations (ROAs) for IP address blocks and autonomous systems, enabling the network to verify the legitimacy of routing announcements with it. This can effectively prevent the spread of false routes and reduce the security risks of inter-domain routing.
[0004] Currently, the deployment of RPKI is being gradually promoted, and more than 50% of IPv4 routes are covered by ROA data. However, the use of ROA data has introduced some new problems, such as resource holders not being able to guarantee synchronous operations at the BGP and ROA levels, the effective time delay of ROA in the routing plane being much greater than the BGP convergence speed, and the ROA data obtained by global relying parties being inconsistent, etc. These problems may all lead to legitimate announcements being judged invalid, causing network operators to be reluctant to promote the deployment of RPKI due to concerns about ROA data.
[0005] In this field, existing research methods have found an abnormal number of invalid declarations and expired ROA files, but they are unable to distinguish which of the excessive invalid declarations are caused by incorrect ROA data or configuration issues of the declarations themselves, nor can they determine whether the expiration of ROA is due to natural expiration or failure to renew on time. In the prior art, to evaluate the effectiveness of the routing verification mechanism, various methods are used to quantitatively analyze the degree of suppression of invalid declarations in the network. One type of method shows the ability of the Internet to limit invalid declarations by analyzing the announcement visibility of the network control plane and the traffic distribution of the data plane; another type of method focuses on exploring the causes of invalid declarations, pointing out that some invalid declarations are not caused by malicious hijacking but by configuration errors or other factors that lead to legitimate announcements being overly restricted. In addition, existing systems have tried to implement alerts for administrators by monitoring the change of the announcement status from valid to invalid, and some statistical models use methods such as multiple linear regression to judge the reasonableness of announcements by analyzing the attribute relationship between the prefix and the source autonomous system in the announcement. Although these methods have solved the problem of detecting abnormal announcements in the network to a certain extent, they generally have problems such as relying on simple state changes or only focusing on local attributes, being unable to fundamentally identify invalid declarations caused by abnormal ROA issuance, and also being difficult to cope with challenges in real scenarios such as short-lived malicious announcements. This makes the further detection and classification of potential ROA anomalies have great limitations. Summary of the Invention
[0006] The present invention aims to solve at least one of the technical problems in the related art to some extent.
[0007] The present invention proposes a system for detecting potential anomalies in route origin authorization based on routing status change analysis, which collects a large amount of multi-source data, extracts and encodes various features, and trains a neural network to complete the classification task. This method includes a data measurement engine, an encoder for the sequence of routing status changes of ROA authorization, and a machine learning classification model for ROA anomalies. The obtained model has strong capabilities in various tasks such as reducing misjudgments of legitimate announcements caused by abnormal ROAs, and is superior to existing state-of-the-art solutions.
[0008] Another object of the present invention is to propose a method for detecting potential anomalies in route origin authorization based on routing status change analysis.
[0009] To achieve the above object, on the one hand, the present invention proposes a system for detecting potential anomalies in route origin authorization based on routing status change analysis, including:
[0010] A data measurement and collection module, which is used to measure the RPKI views of relying parties distributed globally to obtain comprehensive ROA-related data, obtain a prefix status change sequence based on the ROA-related data and routing announcement-related data, and obtain marked ROA anomalies and illegal announcements according to the prefix status change sequence, so as to obtain balanced positive and negative samples based on the marked ROA anomalies and illegal announcements;
[0011] A feature extraction module, which is used to obtain IRR matching degree features based on routing announcement-related data and IRR data, calculate the visibility of observation points and the number of ASs on the propagation path using routing announcement-related data to obtain propagation range features, obtain AS business relationship features based on routing announcement-related data and AS relationship data, and encode the prefix status change sequence to obtain status sequence features;
[0012] A classifier module, which is used to extract feature vectors corresponding to IRR matching degree features, AS business relationship features, propagation range features and status sequence features; input the positive and negative samples into a machine learning model to perform model training based on a preset training strategy, and input the feature vectors into the trained machine learning model for anomaly judgment to output the final anomaly class prediction result.
[0013] The routing origin authorization potential anomaly detection system based on routing status change analysis according to the embodiments of the present invention may also have the following additional technical features:
[0014] In an embodiment of the present invention, the data measurement and collection module is further used for:
[0015] According to the time points of key BGP messages of the routing announcement data source and setting thresholds, obtain the start and end times of each prefix announced by each autonomous system AS to obtain routing announcement-related data;
[0016] Verify and parse the snapshot data at each time point in the ROA data source, and maintain the valid intervals of each ROA to obtain ROA-related data.
[0017] In an embodiment of the present invention, obtaining a prefix status change sequence based on ROA-related data and routing announcement-related data includes:
[0018] According to the start and end times of the current routing announcement, determine and record an announcement duration;
[0019] Obtain ROA data covering all prefixes of the current routing announcement;
[0020] Perform interval calculations on the announcement duration and the validity period of each ROA in the ROA data of all prefixes in turn, and mark the status of each sub-interval as unknown, valid, ASN invalid, and length invalid status to generate a prefix status change sequence.
[0021] In one embodiment of the present invention, obtaining marked ROA anomalies and illegal announcements according to the prefix status change sequence includes:
[0022] Screening out announcements with invalid status during the announcement duration from the prefix status change sequence;
[0023] If the screened announcement finally changes to a valid status, the current situation is regarded as an invalid announcement scenario caused by ROA anomalies;
[0024] If the announcement remains in an invalid status until revocation, the current situation is regarded as an invalid announcement scenario caused by illegal announcements.
[0025] In one embodiment of the present invention, the feature extraction module is further used for:
[0026] Judging whether there is an IRR routing object with an exact prefix match and whether there is an IRR routing object with a parent prefix match in the routing announcement related data and the IRR data. If so, obtain the relevant attributes of the IRR routing object to obtain the IRR matching degree feature;
[0027] Calculating the announcement propagation range of the announcement corresponding to the routing announcement related data at the sampling time point, including calculating the number of observation points of the announcement and the number of autonomous domains on the announcement propagation path to obtain the propagation range feature;
[0028] Calculating the relationship between the autonomous domain AS in the announcement of the routing announcement related data and the AS in the relevant ROA to obtain the AS business relationship feature;
[0029] Calculating the sequence encoding feature of the state change over time of the announcement within the observation interval and before the sampling time through the Transformer Encoder model to obtain the state sequence feature.
[0030] In one embodiment of the present invention, calculating the sequence encoding feature of the state change over time of the announcement within the observation interval and before the sampling time through the Transformer Encoder model to obtain the state sequence feature includes:
[0031] Generating an original feature vector sequence based on the obtained routing announcement status change sequence; wherein, the routing announcement status change sequence includes the status type, status duration, and associated ROA object change situation of each announcement;
[0032] Encoding the changing time information into the original feature vector sequence through Position Encoding to obtain the encoded vector sequence;
[0033] Calculate the correlation between different time points in the encoded vector sequence using multiple self-attention layers, and calculate through a weight matrix to obtain the state sequence features.
[0034] In one embodiment of the present invention, training a machine learning model includes:
[0035] Divide the balanced training samples according to a time window, divide the samples based on historical data before time point t into the training set, and divide the samples after time point t into the test set;
[0036] Initialize the machine learning model parameters, use the feature vector as the input of the machine learning model, input the training set into the machine learning model to calculate the loss function, perform gradient descent training using the Adam optimizer, and use the early stopping strategy to monitor the validation set loss;
[0037] After training is completed, use the test set to evaluate and test the model to obtain the optimal machine learning model.
[0038] In one embodiment of the present invention, the classifier module is further used for:
[0039] Based on a set threshold, perform overly aggressive or lenient anomaly judgments, or use Bayesian methods or methods for dynamically adjusting thresholds to determine the final anomaly category.
[0040] To achieve the above object, another aspect of the present invention proposes a method for detecting potential anomalies in route origin authorization based on route status change analysis, including:
[0041] S1, Measure the RPKI views of relying parties distributed globally to obtain comprehensive ROA-related data, obtain a prefix status change sequence based on the ROA-related data and route announcement-related data, and obtain marked ROA anomalies and illegal announcements based on the prefix status change sequence, so as to obtain balanced positive and negative samples based on the marked ROA anomalies and illegal announcements;
[0042] S2, Obtain IRR matching degree features based on route announcement-related data and IRR data, calculate the visibility of observation points and the number of ASs on the propagation path using route announcement-related data to obtain propagation range features, obtain AS business relationship features based on route announcement-related data and AS relationship data, and encode the prefix status change sequence to obtain state sequence features;
[0043] S3, Extract the feature vectors corresponding to the IRR matching degree features, AS business relationship features, propagation range features, and state sequence features; input the positive and negative samples into the machine learning model for model training based on a preset training strategy, and input the feature vectors into the trained machine learning model for anomaly judgment to output the final anomaly category prediction result.
[0044] The routing origin authorization potential anomaly detection system and method based on routing status change analysis according to the embodiments of the present invention observe ROA objects and corresponding routing entries from the perspective of time series, specifically distinguish and quantify ROA data problems, detect ROA data problems through data measurement and training of deep learning models, and collect multi-dimensional data from multiple data sources while constructing a time series of the ROA life cycle, so as to effectively extract the characteristics of different ROA anomalies and classify them.
[0045] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. Brief Description of the Drawings
[0046] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0047] Figure 1 is a structural diagram of a routing origin authorization potential anomaly detection system based on routing status change analysis according to an embodiment of the present invention;
[0048] Figure 2 is a schematic diagram of the location deployment of experimental facilities in a data measurement platform according to an embodiment of the present invention in the Internet;
[0049] Figure 3 is a flowchart of a routing origin authorization potential anomaly detection method based on routing status change analysis according to an embodiment of the present invention. Detailed Embodiments
[0050] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0051] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0052] The routing origin authorization potential anomaly detection system and method based on routing status change analysis according to an embodiment of the present invention will be described below with reference to the accompanying drawings.
[0053] Figure 1It is a structural diagram of a routing origin authorization potential anomaly detection system based on routing status change analysis according to an embodiment of the present invention. As Figure 1 shown, it includes:
[0054] A data measurement and collection module, which is used to measure the RPKI views of relying parties distributed globally to obtain comprehensive ROA-related data, obtain a prefix status change sequence based on the ROA-related data and routing announcement-related data, and obtain marked ROA anomalies and illegal announcements according to the prefix status change sequence, so as to obtain balanced positive and negative samples based on the marked ROA anomalies and illegal announcements;
[0055] A feature extraction module, which is used to obtain IRR matching degree features based on routing announcement-related data and IRR data, calculate the visibility of observation points and the number of ASs on the propagation path using routing announcement-related data to obtain propagation range features, obtain AS business relationship features based on routing announcement-related data and AS relationship data, and encode the prefix status change sequence to obtain status sequence features;
[0056] A classifier module, which is used to extract feature vectors corresponding to the IRR matching degree features, AS business relationship features, propagation range features and status sequence features; input the positive and negative samples into a machine learning model for model training based on a preset training strategy, and input the feature vectors into the trained machine learning model for anomaly judgment to output the final anomaly class prediction result.
[0057] As Figure 2 shown, it is a schematic diagram of the location deployment of experimental facilities in a data measurement platform in the Internet. The part with a dark background is the facilities controlled by the measurement platform, and the purpose is to collect the global RPKI view. It is a way to collect ROA data from multiple angles proposed by the present invention. In an embodiment of the present invention, based on the Internet resources allocated by APNIC, an RPKI publishing point is built on CERNET to measure global relying parties. According to the obtained relying party access records, the access intervals of different relying parties and the types of relying party software are counted, and the RTR service of the relying party is detected to analyze the integrity of the RPKI views of different relying parties.
[0058] In an embodiment of the present invention, the RPKI views of relying parties (RPs) distributed globally are obtained in a real Internet environment, and the routing announcement data from multiple public data sources on the Internet are cleaned to generate a routing announcement data set and an ROA data set. The routing announcement data set contains a large amount of data of invalid routing announcements; for each announcement, the information saved in the data set covers a large amount of information such as the ROA object, IRR object, observation point and time status change related to the announcement. The ROA data set contains information such as the issuance, expiration, and revocation time of ROAs. The data measurement and collection module is also used for:
[0059] The route announcement data is obtained from the route announcement data source, including the BGP historical data sources in the data set, including but not limited to RIPE RIS and RouteViews and other open source data sets. The data measurement collection processes the route data collected from various sources, and sets the threshold based on the time point of the key BGP message in combination with the algorithm to obtain the start and end time of each prefix announced by each autonomous domain (AS).
[0060] Get ROA related data from ROA data sources, including RPKI historical data sources in the data set, including but not limited to rpkiView and other open source data sets. The data measurement and collection module verifies and analyzes the snapshot data at each time point and maintains the valid interval of each ROA.
[0061] The prefix state change sequence is obtained from the ROA related data and the route announcement related data, including maintaining and recording an announcement duration according to the announcement start and end time, and then analyzing the ROA set of all prefixes covering the announcement, and calculating the announcement duration and the validity period of the ROA in sequence. The algorithm finally marks the state of each sub-interval as unknown, valid, invalid ASN, and invalid length.
[0062] The ROA anomaly and illegal declaration are marked from the prefix state change sequence, including screening out declarations that are in an invalid state during the declaration period. If the declaration eventually changes to a valid state, this situation is regarded as an invalid declaration scenario caused by ROA anomaly; if the declaration remains in an invalid state until it is revoked, it is considered that the declaration is invalid due to its own error, and this situation is regarded as an invalid declaration scenario caused by an illegal declaration.
[0063] From marking ROA anomalies and illegal declarations to balancing positive and negative samples, including in sample labeling, if an invalid declaration eventually turns into a valid state, the time of change is recorded and the sample is marked as a positive sample; if a declaration remains invalid until it is revoked, it is considered that the declaration is invalid due to its own configuration error, and the time point is recorded as a negative sample. To ensure balanced sample data, oversampling or undersampling methods are used during model training to reduce the impact of class imbalance on training results.
[0064] In one embodiment of the present invention, the routing object and the ROA object may change within the observed time range, and whether the invalid declaration is related to the lack of valid ROA can be inferred to a certain extent from the state change before and after the invalid state. The encoder can effectively encode the change of its state over time to help the machine learning model further identify its features. The feature extraction module is also used to:
[0065] Obtain the IRR matching degree features from the routing announcement related data and the IRR data, including determining whether there is an IRR routing object with an exact prefix match and whether there is an IRR routing object with a parent prefix match. If so, obtain the relevant attributes of the IRR routing object.
[0066] Calculate the visibility of the observation point and the number of ASs on the propagation path from the routing announcement related data to obtain the propagation range features, including calculating the announcement propagation range corresponding to the announcement at the above sampling time point, such as the number of observation points where the announcement is observed, the number of autonomous domains on the announcement propagation path, etc.
[0067] Obtain the AS business relationship features from the routing announcement related data and the AS relationship data, including calculating the relationship between the autonomous domain (AS) in the announcement and the AS in the relevant ROA, such as whether they belong to the same organization, etc.
[0068] Encode the state change sequence through the Transformer Encoder model to obtain the state sequence features, including calculating the sequence encoding features of the change of the state of the announcement over time before the sampling time within the observation interval. The specific encoding process is as follows:
[0069] From the routing announcement state change sequence obtained from the above data processing, the state type, state duration, change situation of the associated ROA object, etc. of each announcement can be obtained, generating an original feature vector sequence [[attr1_t1,attr2_t1,…],[attr1_t2,attr2_t2,…],…,[attr1_tn,attr2_tn,…]]; the encoder first encodes the changing time information into the sample features through Position Encoding [attr1,attr2,...]+PositionEncodingLayer(tn); multiple self-attention (Self-Attention) layers are used to calculate the correlation between different time points in the sequence: Attention(Q,K,V)=softmax(\frac{QK^T}{\sqrt{d_k}})V; where, Q (query), K (key), and V (value) all come from the input feature sequence, and the weight matrix is used to learn how a certain time point depends on other time points. In this way, the model can assign different weights between different time points, enabling anomaly detection to not only consider single-point changes but also identify cross-time dependencies.
[0070] In an embodiment of the present invention, a machine learning model is trained on a large number of routing announcement data sets to make full use of vectors encoding time series and other types of information such as announcement propagation range, AS business relationships, and IRR matching degree, so as to learn various features of ROA objects and their related routing announcements for driving classification tasks. The model obtained through machine learning training can analyze real-time ROA data and routing data and complete predictions. The classifier module is further configured to:
[0071] In terms of model selection, a Transformer Encoder model can be used to capture the long-term dependencies of time series, and then a traditional machine learning model (such as Random Forest, XGBoost) is used to classify specific structured features.
[0072] In terms of training strategy, data is divided according to time windows. Samples before time point t based on historical data are used for training, and samples after time point t are used for testing and evaluating generalization ability; K-fold cross-validation is used to evaluate the model stability to ensure that the model can adapt to data changes in different time periods; L1 / L2 regularization is used to prevent the model from overfitting, and the Dropout mechanism is used to reduce the overfitting problem of the neural network.
[0073] During the training process, first, the model parameters are initialized, and the feature vectors obtained from the second part of the processing are used as the model input; then, the training samples are input to calculate the loss function (such as cross-entropy loss); the Adam optimizer is used for gradient descent training; the early stopping strategy is used to monitor the loss of the validation set to avoid overfitting; after the training is completed, the test data is evaluated, and the best model weights are saved.
[0074] Finally, based on the threshold set by the user, overly strict or lenient anomaly judgments are made, and the Bayesian method or the method of dynamically adjusting the threshold can also be used to determine the final anomaly category.
[0075] Using this system, the present invention can detect ROA anomalies that may lead to legal misjudgments, enabling network administrators to be timely reminded to reissue relevant ROAs, thereby preventing legal prefixes from being filtered and subsequent traffic losses.
[0076] In addition, networks that have deployed Route Origin Validation (ROV) can also utilize the detection results to refine their filtering processes, thereby avoiding filtering out legitimate traffic. For example, when Route Origin Authorizations (ROAs) are not published in a timely manner, or when relying parties are unable to obtain a comprehensive global RPKI view, the network can make judgments on the data corresponding to locally detected invalid announcements, and thus can issue a temporary authorization for related ROA anomalies locally as a supplement to the verified ROA, and transmit it to the border router through the RTR protocol to construct the filtering table.
[0077] The beneficial effects of the present invention are as follows:
[0078] 1) Support for consistency analysis of the RPKI view. Based on the publishing points deployed according to the present invention, access information from relying parties (RPs) in different countries, regions, and organizations around the world can be collected, and the RPKI views of some of these relying parties can be detected and obtained, and further analyze the consistency between them. Based on the results of the above consistency analysis, the present invention finds that there are inconsistencies in the RPKI views of RPs from different regions of the world, which proves the necessity and criticality of ROA data anomaly detection.
[0079] 2) Analyze the validity of ROAs from the time dimension. By analyzing the time series of the ROA life cycle, the present invention can identify the absence of valid ROAs caused by reissuance gaps, and by analyzing the changes in the routing announcement status related to ROAs, the present invention can identify the absence of valid ROAs caused in part by signing delays and signing expirations.
[0080] 3) Powerful data measurement engine. Data related to the ownership of Internet resources has characteristics such as diverse sources, huge data volumes, and complex formats. If data is collected from only a single or a small number of sources, there will be problems of insufficient analysis. The data measurement and collection module of the present invention widely collects various types of data, optimizes the storage format, and automatically performs verification and comparison. Therefore, problems that can only be discovered through cross-comparison of a large number of data sources can also be effectively analyzed by the technical solution of the present invention.
[0081] 4) Capable of real-time analysis of newly generated routing announcements and ROA data on the Internet. After the machine learning classifier model of the present invention is trained, the data measurement and collection module of the present invention can work regularly or continuously, continuously collect newly generated routing announcement data and ROA data, which can be used for various downstream tasks after processing, and realize real-time monitoring and analysis of routing announcements and ROA data on the Internet.
[0082] 5) It is able to specifically distinguish and quantitatively analyze ROA data problems. Existing other technical solutions generally have problems such as relying on simple state changes or only focusing on local attributes. By collecting data from multiple sources and dimensions, the present invention can track the complete life cycle of routing objects and ROA objects, record and express their state changes and transitions, and thus analyze data problems more comprehensively.
[0083] 6) Wide application potential. Since the model of the present invention performs excellently in a variety of downstream tasks, it is not limited to specific application scenarios, but can be widely applied to multiple fields of routing announcement and ROA data analysis and processing.
[0084] Generally speaking, through its innovative learning method and powerful technical framework, the present invention provides a more efficient, accurate and adaptable solution in the aspects of routing announcement, ROA data analysis and ROA anomaly classification tasks.
[0085] According to the routing origin authorization potential anomaly detection system based on routing status change analysis of an embodiment of the present invention, by collecting multi-dimensional data from multiple data sources and simultaneously constructing a time series of the ROA life cycle, it effectively extracts the characteristics of different ROA anomalies and classifies them. This method combines an efficient data measurement engine, a powerful ROA life cycle time series encoder and an accurate ROA anomaly machine learning classification model. The data measurement engine obtains the RPKI views of relying parties (RPs) distributed globally in a real Internet environment, extracts useful information from a large number of ROA-related data sources, and provides rich training data for subsequent model training. The ROA life cycle time series encoder adopts an advanced neural network structure, makes full use of information such as the announced state changes related to ROA, and realizes the efficient encoding of the ROA life cycle time series by combining routing plane information. The ROA anomaly machine learning classification model detects anomalies based on features such as time series encoding, announced propagation range, autonomous system (AS) business relationship and IRR matching degree. The obtained model shows strong capabilities in various downstream tasks, such as classifying ROA anomaly types. The present invention can timely detect invalid announcements caused by the lack of valid ROAs, thereby preventing network connection interruptions and loss of legitimate traffic caused by misjudgments. The method of the present invention outperforms existing state-of-the-art solutions in the performance of related tasks, showing great application potential and practical value.
[0086] To implement the above embodiment, as Figure 3 shown, the present embodiment also provides a routing origin authorization potential anomaly detection method based on routing status change analysis, including:
[0087] S1. Measure the RPKI views of relying parties distributed globally to obtain comprehensive ROA-related data, obtain a prefix status change sequence based on the ROA-related data and routing announcement-related data, and obtain marked ROA anomalies and illegal announcements according to the prefix status change sequence, so as to obtain balanced positive and negative samples based on the marked ROA anomalies and illegal announcements;
[0088] S2. Obtain IRR matching degree features based on routing announcement-related data and IRR data, calculate the visibility of observation points and the number of ASs on the propagation path using the routing announcement-related data to obtain propagation range features, obtain AS business relationship features based on the routing announcement-related data and AS relationship data, and encode the prefix status change sequence to obtain status sequence features;
[0089] S3. Extract the feature vectors corresponding to the IRR matching degree features, AS business relationship features, propagation range features, and status sequence features; input the positive and negative samples into a machine learning model for model training based on a preset training strategy, and input the feature vectors into the trained machine learning model for anomaly judgment to output the final anomaly category prediction result.
[0090] According to the multi-source remote sensing image change detection method of the embodiments of the present invention, the specific distinction and quantification of ROA data problems of ROA objects and corresponding routing entries are observed from the perspective of time series, and the ROA data problems are detected through data measurement and training of a deep learning model. It can timely detect invalid announcements caused by the lack of valid ROAs, thereby preventing network connection interruptions and the loss of legitimate traffic caused by misjudgments. The method of the present invention outperforms existing state-of-the-art solutions in the performance of related tasks, showing great application potential and practical value.
[0091] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0092] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.
Claims
1. A system for detecting potential anomalies of routing origin authorization based on routing state change analysis, characterized in that: include: A data measurement and collection module is used to measure the RPKI views of the relying parties distributed around the world to obtain comprehensive ROA-related data, obtain a prefix state change sequence based on the ROA-related data and the route announcement-related data, and obtain marked ROA anomalies and illegal announcements based on the prefix state change sequence, so as to obtain balanced positive and negative samples based on the marked ROA anomalies and illegal announcements; A feature extraction module is used to obtain an IRR matching feature based on route announcement related data and IRR data, calculate the visibility of the observation point and the number of ASs on the propagation path using the route announcement related data to obtain a propagation range feature, obtain an AS business relationship feature based on the route announcement related data and AS relationship data, and encode the prefix state change sequence to obtain a state sequence feature; The classifier module is used to extract feature vectors corresponding to IRR matching features, AS business relationship features, propagation range features and state sequence features; input the positive and negative samples into the machine learning model to perform model training based on a preset training strategy, and input the feature vectors into the trained machine learning model for anomaly judgment to output the final anomaly category prediction result.
2. The system according to claim 1, characterized in that The data measurement collection module is also used to: According to the time point of the key BGP message of the route announcement data source, the threshold is set to obtain the start and end time of each prefix announced by each autonomous domain AS, so as to obtain the route announcement related data; Verify and analyze the snapshot data at each time point in the ROA data source, and maintain the valid interval of each ROA to obtain ROA related data.
3. The system according to claim 2, characterized in that The prefix state change sequence is obtained based on the ROA related data and the route announcement related data, including: According to the start and end time of the current route announcement, determine and record an announcement duration; Get ROA data covering all prefixes announced by the current route; The declaration duration and the validity period of each ROA in the ROA data of all prefixes are calculated in intervals in turn, and the state of each sub-interval is marked as unknown, valid, ASN invalid, and length invalid to generate a prefix state change sequence.
4. The system according to claim 3, characterized in that According to the prefix state change sequence, the ROA anomaly and illegal declaration are obtained, including: Filter out declarations with invalid states during the declaration duration from the prefix state change sequence; If the filtered declaration eventually changes to a valid state, the current situation will be regarded as an invalid declaration scenario caused by ROA anomaly; If the declaration remains invalid until revoked, the current situation will be considered an invalid declaration scenario resulting from an illegal declaration.
5. The system according to claim 4, characterized in that The feature extraction module is also used to: Determine whether there is an IRR routing object with an exact prefix match and an IRR routing object with a parent prefix match in the routing announcement related data and the IRR data. If so, obtain the relevant attributes of the IRR routing object to obtain the IRR matching degree feature; Calculate the announcement propagation range of the announcement corresponding to the route announcement related data at the sampling time point, including calculating the number of observation points of the announcement and the number of autonomous domains on the announcement propagation path, so as to obtain the propagation range characteristics; Calculate the relationship between the autonomous domain AS in the announcement of the route announcement related data and the AS in the related ROA to obtain the AS business relationship characteristics; The Transformer Encoder model is used to calculate the sequence encoding features of the state changes over time within the observation interval and before the sampling time to obtain the state sequence features.
6. The system according to claim 5, characterized in that The Transformer Encoder model is used to calculate the sequence encoding features of the state changes over time declared within the observation interval and before the sampling time to obtain the state sequence features, including: Generate an original feature vector sequence based on the acquired route announcement state change sequence; wherein the route announcement state change sequence includes the state type, state duration, and associated ROA object change of each announcement; The changing time information is encoded into the original feature vector sequence through Position Encoding to obtain the encoded vector sequence; Multiple self-attention layers are used to calculate the correlation between different time points in the encoded vector sequence, and the weight matrix is calculated to obtain the state sequence characteristics.
7. The system according to claim 1, characterized in that Training machine learning models, including: The balanced training samples are divided into data according to the time window. The samples before the time point t based on the historical data are divided into the training set, and the samples after the time point t are divided into the test set; Initialize the machine learning model parameters, use the feature vector as the input of the machine learning model, input the training set into the machine learning model to calculate the loss function, use the Adam optimizer for gradient descent training, and use the early stopping strategy to monitor the validation set loss; After the training is completed, the model is evaluated using the test set to obtain the optimal machine learning model.
8. The system according to claim 1, characterized in that The classifier module is also used to: Based on the set threshold, an overly aggressive or relaxed abnormal judgment is made, or the final abnormal category is determined by using the Bayesian method or the method of dynamically adjusting the threshold.
9. A method for detecting potential anomalies of routing origin authorization based on routing state change analysis, characterized in that: include: Measure the RPKI views of relying parties distributed around the world to obtain comprehensive ROA-related data, obtain prefix state change sequences based on the ROA-related data and route announcement-related data, and obtain marked ROA anomalies and illegal announcements based on the prefix state change sequences, so as to obtain balanced positive and negative samples based on the marked ROA anomalies and illegal announcements; Based on the route announcement related data and IRR data, the IRR matching degree feature is obtained. The route announcement related data is used to calculate the visibility of the observation point and the number of ASs on the propagation path to obtain the propagation range feature. Based on the route announcement related data and AS relationship data, the AS business relationship feature is obtained. In addition, the prefix state change sequence is encoded to obtain the state sequence feature. Extract feature vectors corresponding to IRR matching features, AS business relationship features, propagation range features, and state sequence features; input the positive and negative samples into the machine learning model to perform model training based on a preset training strategy, and input the feature vectors into the trained machine learning model for anomaly judgment to output the final anomaly category prediction result.