BGP Route Validation for Autonomous System Hijack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing BGP systems face challenges in safely propagating data through autonomous systems due to faulty or malicious transit providers, leading to network outages and hijacking issues, as they lack secure authentication and shared routing policies across separate autonomous systems.
Innovation Solution
A method is introduced where a victim autonomous system sends a message to other ASs to avoid using specific AS numbers associated with network issues, including a list of AS numbers to avoid, a timestamp, a signature for authentication, and an identifier for certificate verification, to prevent data propagation through faulty or hijacked routes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If BGP routing is used for data propagation across autonomous systems, then data transmission capability is improved, but network security and reliability deteriorate due to faulty or malicious transit providers
Solution Approach 1:
The patent introduces a BGP route validation system that acts as an intermediary between autonomous systems. This validation system verifies the authenticity and safety of BGP routes before they are accepted and propagated, preventing malicious or faulty routes from compromising network security while maintaining data transmission capability.
Solution Approach 2:
The patent implements a feedback mechanism where autonomous systems report suspicious or malicious BGP routes to a central validation system. The validation system processes these reports and updates route validation policies, creating a continuous feedback loop that improves network security over time while maintaining routing functionality.
2Speed
If BGP routes are propagated without validation, then routing speed and simplicity are improved, but the ability to detect and prevent hijacking deteriorates
Solution Approach 1:
The patent applies preliminary action by validating BGP routes before they are propagated across the network. The validation system checks route authenticity, owner authorization, and potential maliciousness in advance, allowing fast propagation of validated routes while preventing hijacking detection issues from arising.
Solution Approach 2:
The patent implements preliminary anti-action by preemptively blocking potentially malicious BGP routes through validation before they can cause harm. The system identifies and rejects suspicious routes in advance, preventing hijacking attempts before they can compromise network security.
3Adaptability or versatility
If autonomous systems operate independently without shared policies, then system autonomy and flexibility are improved, but the ability to coordinate security responses deteriorates
Solution Approach 1:
The patent introduces a universal BGP route validation framework that can be adopted by any autonomous system independently. Each system maintains its autonomy while participating in the common validation ecosystem, allowing universal security improvements without sacrificing individual system flexibility or independence.
Data Source
AI summary
Techniques for mitigating BGP blackholes and hijackings are disclosed herein. The techniques include methods for determining, by a victim autonomous system (AS), that a first AS is associated with a first BGP route that includes the victim AS as the destination or as an AS along the first BGP route to the destination and sending a message to a second AS directing the second AS to refrain from using the first AS to propagate data to the victim AS. The message can include a set of one or more AS numbers to avoid in refraining from using to propagate data to the victim AS, a timestamp, an expiration interval, a signature of the victim AS, and an identifier identifying a certificate to be used to verify the signature. Systems and computer-readable media are also provided.


