Prefix Hijacker Localization via AS-Level Path Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures are inadequate in preventing prefix hijacking, where a malicious BGP router announces false routes, leading to IP traffic diversion and potential denial of service or phishing attacks, as existing inter-domain routing protocols rely on implicit trust and lack effective mechanisms to identify hijackers within a one-hop neighborhood.
Innovation Solution
A method and system that generate one-hop neighborhoods from autonomous system-level paths reported by monitors, calculate the frequency and distance of AS identifiers, and identify a suspect set of AS identifiers with the highest counts and distances to pinpoint potential prefix hijackers within a one-hop neighborhood.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If BGP routers rely on implicit trust for inter-domain routing, then routing simplicity is maintained, but security against prefix hijacking deteriorates
Solution Approach 1:
The system performs preliminary actions by deploying monitors throughout the network to continuously collect and report AS-level path information before hijacking can occur. This advance preparation enables rapid detection and localization of prefix hijackers when anomalies are detected, without requiring fundamental changes to BGP trust assumptions
Solution Approach 2:
The patent introduces an intermediary detection system that sits between legitimate BGP routing and hijacked routing. The monitors and analysis system act as intermediaries to observe, analyze, and identify hijacking attempts without disrupting normal BGP operations, thereby maintaining routing simplicity while adding security
2Measurement precision
If comprehensive monitoring of AS-level paths is implemented, then hijacker detection capability is improved, but system complexity increases
Solution Approach 1:
The detection system is segmented into independent, distributed monitors deployed throughout the network, each performing simple path collection and reporting. This segmentation avoids centralized complexity while achieving comprehensive monitoring coverage through multiple simple agents working in parallel
Solution Approach 2:
The monitors are designed to autonomously collect AS-level path information and self-report to the analysis system without requiring complex manual configuration or management. The system serves itself by automatically processing the reported data to identify suspect ASes and generate alerts
3Measurement precision
If the suspect set of AS identifiers is reduced to one-hop neighborhood, then localization precision is improved, but the scope of investigation is reduced
Solution Approach 1:
The system uses another dimension (AS-level path information from multiple monitors) to constrain the search space. By analyzing the intersection of paths from multiple monitoring points, the system can precisely localize hijackers to one-hop neighborhoods without arbitrarily limiting the investigation scope, as the precision emerges from multi-dimensional path analysis
Data Source
AI summary
Method, system and computer-readable medium to locate a prefix hijacker of a destination prefix within a one-hop neighborhood on a network. The method includes generating one-hop neighborhoods from autonomous system (AS)-level paths of plural monitors to a destination prefix. The method also includes determining a suspect set of AS identifiers resulting from a union of the one-hop neighborhoods. The method further includes calculating a count and a distance associated with each AS identifier of the suspect set. The count indicates how often the AS identifier appeared in the one-hop neighborhoods. The distance indicates a total distance from the AS identifier to AS identifiers associated with the plural monitors. Yet further, the method includes generating a one-hop suspect set of AS identifiers from the suspect set that have highest counts and highest distances.


