BGP Prefix Hijacking Detection via Traffic Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mechanisms are ineffective in detecting prefix hijacking attacks in Internet routing systems, as they lack explicit authentication mechanisms and rely on outdated and inconsistent routing information databases, making it challenging to identify bogus routing information and trace the origin of anomalous route announcements.
Innovation Solution
A method for generating prefix hijacking alerts by identifying anomalous prefixes and correlating them with network traffic anomalies using a system that analyzes BGP routing updates and network traffic flows, building on historical routing data to establish valid associations between prefixes and their origin Autonomous Systems, thereby reducing reliance on poorly maintained WHOIS databases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If BGP routing information is exchanged between Autonomous Systems, then routing flexibility and adaptability are improved, but authentication reliability deteriorates due to implicit trust without explicit verification mechanisms
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors BGP route announcements, compares them against archived historical data, and provides real-time verification feedback. When a route announcement is received, the system queries archived data to verify consistency and authenticity, creating a closed-loop authentication system that maintains routing flexibility while ensuring reliability through continuous verification.
Solution Approach 2:
The patent performs preliminary action by archiving and storing historical BGP route announcement data before attacks occur. This pre-stored historical data serves as a baseline for detecting anomalies, allowing the system to identify prefix hijacking attacks and other routing abnormalities by comparing current announcements against the archived historical record, thus enabling proactive detection rather than reactive response.
2Reliability
If route filters are deployed to prevent prefix hijacking, then security is improved, but detection accuracy deteriorates due to ad-hoc configuration and inability to identify anomalous activities
Solution Approach 1:
The system implements feedback by continuously monitoring network traffic patterns and comparing them against expected behavior derived from archived routing data. When traffic anomalies are detected that correspond to hijacked prefixes, the system provides real-time feedback alerts, enabling precise detection of prefix hijacking attacks and other anomalous activities that ad-hoc filters cannot identify.
Solution Approach 2:
The patent replaces the mechanical ad-hoc route filtering system with an automated data-driven detection system. Instead of relying on manually configured filters that lack precision, the system uses automated comparison of archived historical data with current routing announcements and traffic patterns, substituting mechanical filtering with intelligent data analysis to achieve high-precision detection of prefix hijacking and other routing abnormalities.
3Quantity of substance
If WHOIS databases are used for routing information authentication, then information availability is improved, but data consistency and reliability deteriorate due to human-induced errors and lack of real-time updates
Solution Approach 1:
The patent performs preliminary action by continuously archiving and storing historical BGP route announcement data as it occurs. This creates a real-time historical database that is automatically updated with each route change, eliminating the need to rely on static WHOIS databases that are manually maintained. The archived data provides a consistent, real-time baseline for authentication that prevents human-induced errors and ensures data consistency.
Solution Approach 2:
The system implements self-service by automatically maintaining its own historical routing data through continuous archiving of BGP announcements. Rather than relying on external WHOIS databases that require manual updates and human maintenance, the system self-updates its reference data using automated processes, ensuring real-time consistency and eliminating human errors in data maintenance while maintaining comprehensive information availability.
Data Source
AI summary
The invention relates to a method for generating a prefix hijacking alert in a network, wherein a plurality of network traffic flows are routed based at least on a plurality of prefix announcements from one or more Border Gateway Protocol (BGP) router, the method comprises identifying an anomalous prefix from the plurality of prefix announcements, identifying a network traffic anomaly from the plurality of network traffic flows, and correlating the anomalous prefix and the network traffic anomaly to generate the prefix hijacking alert.


