BGP Hijack Mitigation via Automatic More-Specific Route Prefixes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Border Gateway Protocol (BGP) hijacks pose a significant security threat by causing Internet traffic misrouting due to malicious manipulation of BGP routing data, which existing technologies have not adequately addressed.
Innovation Solution
The system automatically announces more-specific route prefixes when a netblock is hijacked and withdraws them when the hijack is resolved, using a processor to determine hijack attributes, generate replacement prefixes, and send BGP updates to routers, thereby mitigating the impact of BGP hijacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If more-specific route prefixes are announced to override malicious BGP routes, then traffic misrouting is reduced and security is improved, but routing table complexity and information overload increase
Solution Approach 1:
The patent segments the affected netblock into multiple more-specific route prefixes (e.g., dividing a /22 block into four /24 prefixes). This segmentation allows the system to override malicious routes with granular, precise prefixes that target only the affected portions of the netblock, reducing unnecessary routing information propagation while maintaining security.
Solution Approach 2:
The patent applies local quality by generating more-specific route prefixes that are tailored to the exact scope of the hijacked netblock. Instead of announcing broad less-specific routes that affect entire netblocks, the system creates precisely scoped prefixes that match the hijacked portions, thereby providing targeted security mitigation without overwhelming the routing system with excessive information.
2Reliability
If more-specific replacement routing prefixes are generated and propagated, then malicious route override is achieved, but device complexity and processing overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-generating more-specific replacement routing prefixes based on the structure of the hijacked netblock. The system prepares these prefixes in advance using automated algorithms that analyze the netblock attributes and generate appropriate more-specific prefixes, reducing the complexity of real-time response while ensuring security.
Solution Approach 2:
The patent applies self-service by enabling the routing system to automatically generate, propagate, and manage more-specific replacement prefixes without requiring manual intervention. The system autonomously detects hijacks, generates appropriate prefixes, and propagates them through the BGP network, reducing operational complexity while maintaining high security standards.
3Stability of the object's composition
If automatic withdrawal of more-specific prefixes is implemented when hijack stops, then routing stability is improved, but detection precision and timing requirements increase
Solution Approach 1:
The patent implements feedback by continuously monitoring BGP route announcements and detecting when hijacked netblocks are no longer being maliciously advertised. The system uses feedback from BGP updates to determine when to withdraw the more-specific replacement prefixes, ensuring routing stability while maintaining precise detection of hijack status changes through automated monitoring mechanisms.
Data Source
AI summary
Systems, methods, and devices of the various embodiments may enable the reduction of the impact of Border Gateway Protocol (BGP) hijacks by automatically announcing more-specific route prefixes when a netblock is hijacked. In various embodiments, the more-specific route prefixes may be automatically withdrawn when the netblock hijacking stops.


