skip to main content
10.1145/2513228.2513292acmconferencesArticle/Chapter ViewAbstractPublication PagesracsConference Proceedingsconference-collections
research-article

The BGP monitoring and alarming system to detect and prevent anomaly IP prefix advertisement

Published:01 October 2013Publication History

ABSTRACT

The Border Gateway Protocol (BGP) is the routing protocol that enables large IP networks to form a single Internet. The main objective of BGP is to exchange Network Layer Reachability Information (NLRI) between Autonomous Systems (ASes) so that a BGP speaker can announce their IP prefix and find a path to the destination of packets. However, a BGP hijacker can pretend to be any third BGP speaker because BGP itself doesn't have the functionality of validating BGP messages. In order to solve this problem, BGP speaker needs to validate messages coming from other BGP speakers. In this paper, we propose the BGP Monitoring and Alarm System (BGPMAS) which monitors incoming announcements and starts to make sounds of the alarm if the BGPMAS detects an invalid announcement. In addition, the BGPMAS provides AS administrators with web service to show where the invalid message is coming from so that the administrators can rapidly deal with the IP prefix hijacking by ignoring the malicious BGP router's prefix. In order to set this environment, the BGPMAS needs to be connected to the BGP router and the AS administrator needs the Alarm Application (AA) which will make sounds of the alarm and the AA receives a signal from the BGPMAS when the BGPMAS detect an invalid announcement. As a result, the BGP routers can easily have the RPKI-based origin validation function with the BGPMAS.

References

  1. Rekhter, Y. 2006. A Border Gateway Protocol 4 (BGP-4). RFC 4271.Google ScholarGoogle Scholar
  2. Murphy, S. 2006. BGP Security Vulnerabilities Analysis. RFC 4272.Google ScholarGoogle Scholar
  3. "7007 Explanation and Apology," Apr 1997, http://www.merit.edu/mail.archives/nanog/1997-04/msg00444.html.Google ScholarGoogle Scholar
  4. Rensys Blog, Con-Ed Steals the 'Net. {Online}. Available: http://www.renesys.com/blog/2006/01/coned_steals_the_net.shtmlGoogle ScholarGoogle Scholar
  5. Rensys Blog, Internet-Wide Catastrophe Last Year {Online}. Available: http://www.renesys.com/blog/2005/12/internetwide_nearcatastrophela.shtmlGoogle ScholarGoogle Scholar
  6. Rensys Blog, Pakistan hijacks YouTube {Online}. Available: http://www.renesys.com/blog/2008/02/pakistan_hijacks_youtube_1.shtmlGoogle ScholarGoogle Scholar
  7. Lad, M., Massey, D., Pei, D., Wu, Y., Zhang, B., and Zhang, L. 2006. PHAS: A prefix hijack alert system. In Proceedings of the 15th conference on USENIX Security Symposium - Volume 15 (USENIX-SS'06), Vol. 15. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. Kent, S., Lynn, C., and Seo, K. 2000. Secure Border Gateway Protocol (S-BGP). IEEE Journal on Selected Areas in Communications. 18, 4 (Apr. 2000) Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. Van Oorschot, P., Wan T., and Kranakis, E. 2007. On Interdomain Routing Security and Pretty Secure BGP (psBGP). ACM Transactions on Information and System Security. 10, 3(July 2007). Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. Lepinski, M., Kent, S., and Kong, D. 2012. A Profile for Route Origin Authorizations (ROAs). Work in progress (Internet Draft), Feb 2012.Google ScholarGoogle Scholar
  11. Mohapatra, P. 2013. BGP Prefix Origin Validation State Extended Community. draft-ietf-sidr-origin-validation-signaling-02(Dec 2012).Google ScholarGoogle Scholar
  12. White, R. 2003. Securing BGP through secure origin BGP. Internet Protocol Journal. 6, 3 (September 2003).Google ScholarGoogle Scholar
  13. BGP Secure Routing Extension (BGP-SRx) by NIST {Online}. Availble: http://www-x.antd.nist.gov/bgpsrx/Google ScholarGoogle Scholar
  14. Karlin, J., Forrest, S., and Rexford, J. 2006. Pretty Good BGP: Improving BGP by Cautiously Adopting Routes. In IEEE International Conference on Network Protocols. Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. Manderson, T., Vegoda, L., and Kent, S. 2012. Resource Public Key Infrastructure (RPKI) Objects Issued by IANA(Feb. 2012). {Online}. Available: http://www.rfc-editor.org/rfc/rfc6491.txtGoogle ScholarGoogle Scholar

Index Terms

  1. The BGP monitoring and alarming system to detect and prevent anomaly IP prefix advertisement

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Conferences
            RACS '13: Proceedings of the 2013 Research in Adaptive and Convergent Systems
            October 2013
            529 pages
            ISBN:9781450323482
            DOI:10.1145/2513228

            Copyright © 2013 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 1 October 2013

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • research-article

            Acceptance Rates

            RACS '13 Paper Acceptance Rate73of317submissions,23%Overall Acceptance Rate393of1,581submissions,25%
          • Article Metrics

            • Downloads (Last 12 months)5
            • Downloads (Last 6 weeks)0

            Other Metrics

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader