BGP Hijack Mitigation via Automatic More-Specific Route Prefixes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Border Gateway Protocol (BGP) hijacks pose a significant security threat by causing Internet traffic misrouting due to malicious manipulation of BGP routing data, which existing technologies have not adequately addressed.

Innovation Solution

The system automatically announces more-specific route prefixes when a netblock is hijacked and withdraws them when the hijack is resolved, using a processor to determine hijack attributes, generate replacement prefixes, and send BGP updates to routers, thereby mitigating the impact of BGP hijacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If more-specific route prefixes are announced to override malicious BGP routes, then traffic misrouting is reduced and security is improved, but routing table complexity and information overload increase

Engineering Contradiction:
Improvetraffic routing reliabilityVSAvoidrouting information overload
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the affected netblock into multiple more-specific route prefixes (e.g., dividing a /22 block into four /24 prefixes). This segmentation allows the system to override malicious routes with granular, precise prefixes that target only the affected portions of the netblock, reducing unnecessary routing information propagation while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by generating more-specific route prefixes that are tailored to the exact scope of the hijacked netblock. Instead of announcing broad less-specific routes that affect entire netblocks, the system creates precisely scoped prefixes that match the hijacked portions, thereby providing targeted security mitigation without overwhelming the routing system with excessive information.

Inventive Principle:
Principle #3Local quality

2Reliability

If more-specific replacement routing prefixes are generated and propagated, then malicious route override is achieved, but device complexity and processing overhead increase

Engineering Contradiction:
Improveroute securityVSAvoidrouting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-generating more-specific replacement routing prefixes based on the structure of the hijacked netblock. The system prepares these prefixes in advance using automated algorithms that analyze the netblock attributes and generate appropriate more-specific prefixes, reducing the complexity of real-time response while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies self-service by enabling the routing system to automatically generate, propagate, and manage more-specific replacement prefixes without requiring manual intervention. The system autonomously detects hijacks, generates appropriate prefixes, and propagates them through the BGP network, reducing operational complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If automatic withdrawal of more-specific prefixes is implemented when hijack stops, then routing stability is improved, but detection precision and timing requirements increase

Engineering Contradiction:
Improverouting table stabilityVSAvoidhijack detection precision
Core Design Contradiction:
Stability of the object's compositionVSMeasurement precision

Solution Approach 1:

The patent implements feedback by continuously monitoring BGP route announcements and detecting when hijacked netblocks are no longer being maliciously advertised. The system uses feedback from BGP updates to determine when to withdraw the more-specific replacement prefixes, ensuring routing stability while maintaining precise detection of hijack status changes through automated monitoring mechanisms.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11736518B2Reducing the impact of border gateway protocol (BGP) hijacks
Publication Date: 2023.08.22 CHARTER COMM OPERATING LLC
  • US11736518B2 patent drawing
  • US11736518B2 patent drawing
  • US11736518B2 patent drawing

AI summary

Systems, methods, and devices of the various embodiments may enable the reduction of the impact of Border Gateway Protocol (BGP) hijacks by automatically announcing more-specific route prefixes when a netblock is hijacked. In various embodiments, the more-specific route prefixes may be automatically withdrawn when the netblock hijacking stops.