BGP Route Validation for Autonomous System Hijack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing BGP systems face challenges in safely propagating data through autonomous systems due to faulty or malicious transit providers, leading to network outages and hijacking issues, as they lack secure authentication and shared routing policies across separate autonomous systems.

Innovation Solution

A method is introduced where a victim autonomous system sends a message to other ASs to avoid using specific AS numbers associated with network issues, including a list of AS numbers to avoid, a timestamp, a signature for authentication, and an identifier for certificate verification, to prevent data propagation through faulty or hijacked routes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If BGP routing is used for data propagation across autonomous systems, then data transmission capability is improved, but network security and reliability deteriorate due to faulty or malicious transit providers

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a BGP route validation system that acts as an intermediary between autonomous systems. This validation system verifies the authenticity and safety of BGP routes before they are accepted and propagated, preventing malicious or faulty routes from compromising network security while maintaining data transmission capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where autonomous systems report suspicious or malicious BGP routes to a central validation system. The validation system processes these reports and updates route validation policies, creating a continuous feedback loop that improves network security over time while maintaining routing functionality.

Inventive Principle:
Principle #23Feedback

2Speed

If BGP routes are propagated without validation, then routing speed and simplicity are improved, but the ability to detect and prevent hijacking deteriorates

Engineering Contradiction:
Improverouting speedVSAvoidhijack detection capability
Core Design Contradiction:
SpeedVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by validating BGP routes before they are propagated across the network. The validation system checks route authenticity, owner authorization, and potential maliciousness in advance, allowing fast propagation of validated routes while preventing hijacking detection issues from arising.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements preliminary anti-action by preemptively blocking potentially malicious BGP routes through validation before they can cause harm. The system identifies and rejects suspicious routes in advance, preventing hijacking attempts before they can compromise network security.

Inventive Principle:
Principle #9Preliminary anti-action

3Adaptability or versatility

If autonomous systems operate independently without shared policies, then system autonomy and flexibility are improved, but the ability to coordinate security responses deteriorates

Engineering Contradiction:
Improvesystem autonomyVSAvoidsecurity coordination
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a universal BGP route validation framework that can be adopted by any autonomous system independently. Each system maintains its autonomy while participating in the common validation ecosystem, allowing universal security improvements without sacrificing individual system flexibility or independence.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240163311A1BGP blackhole and hijack mitigation
Publication Date: 2024.05.16 CISCO TECHNOLOGY INC
  • US20240163311A1 patent drawing
  • US20240163311A1 patent drawing
  • US20240163311A1 patent drawing

AI summary

Techniques for mitigating BGP blackholes and hijackings are disclosed herein. The techniques include methods for determining, by a victim autonomous system (AS), that a first AS is associated with a first BGP route that includes the victim AS as the destination or as an AS along the first BGP route to the destination and sending a message to a second AS directing the second AS to refrain from using the first AS to propagate data to the victim AS. The message can include a set of one or more AS numbers to avoid in refraining from using to propagate data to the victim AS, a timestamp, an expiration interval, a signature of the victim AS, and an identifier identifying a certificate to be used to verify the signature. Systems and computer-readable media are also provided.