skip to main content
10.1145/637201.637231acmconferencesArticle/Chapter ViewAbstractPublication PagesimcConference Proceedingsconference-collections
Article

Observation and analysis of BGP behavior under stress

Published:06 November 2002Publication History

ABSTRACT

Despite BGP's critical importance as the de-facto Internet inter-domain routing protocol, there is little understanding of how BGP actually performs under stressful conditions when dependable routing is most needed. In this paper, we examine BGP's behavior during one stressful period, the Code Red/Nimda attack on September 18, 2001. The attack was correlated with a 30-fold increase in the BGP update messages at a monitoring point which peers with a number of Internet service providers. Our examination of BGP's behavior during the event concludes that BGP exhibited no significant abnormality, and that over 40% of the observed updates can be attributed to the monitoring artifact in current BGP measurement settings. Our analysis, however, does reveal several weak points in both the protocol and its implementation, such as BGP's sensitivity to the transport session reliability, its inability to avoid the global propagation of small local changes, and its certain implementation features whose otherwise benign effects only get amplified under stressful conditions. We also identify areas for improvement in the current network measurement and monitoring effort.

References

  1. Y. Rekhter and T. Li, "Border Gateway Protocol 4," RFC 1771, July 1995. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. J. Cowie, A. Ogielski, B. J. Premore, and Y. Yuan, "Global routing instabilities triggered by Code Red II and Nimda worm attacks," Tech. Rep., Renesys Corporation, Dec 2001.Google ScholarGoogle Scholar
  3. Networking System Adminisration and Security Institute (SANS), "Nimda worm/virus report," http://www.incidents.org/react/nimda.pdf.Google ScholarGoogle Scholar
  4. RIPE, "Routing Information Service Project," http://www.ripe.net/ripencc/pub-services/np/ris-index.html.Google ScholarGoogle Scholar
  5. C. Labovitz, A. Ahuja, A. Bose, and E Jahanian, "Delayed Internet routing convergence," in Proceedings of the ACM SIGCOMM, August/September 2000. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. C. Labovitz, G. R. Malan, and F. Jahanian, "Origins of internet routing instability," in Proceedings of the IEEE INFOCOM "99, New York, NY, March 1999, pp. 218--26.Google ScholarGoogle Scholar
  7. Cisco Systems, "Dealing with mallocfail and high cpu utilization resulting from the "code red" worm," http://www.cisco.com/warp/public/63/ts_codred_worm.shtml.Google ScholarGoogle Scholar
  8. D. Pei, X. Zhao, L. Wang, D. Massey, A. Mankin, S. Wu, and L. Zhang, "Improving BGP convergence through consistency assertions," in Proceedings of the IEEE INFOCOM, June 2002.Google ScholarGoogle Scholar
  9. C. Labovitz, G. R. Malan, and F. Jahanian, "Internet routing instability," in Proceedings of the ACM SIGCOMM '97, Cannes, France, September 1997, pp. 115--26. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. G.R. Malan and F. Jahanian, "An extensible probe architecture for network protocol performance measurement," in Proceedings of the ACM SIGCOMM '98, Vancouver, BC, Canada, September 1998. Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. A. Shaikh, A. Varma, L. Kalampoukas, and R. Dube, "Routing stability in congested networks: Experimentation and analysis," in Proceedings of the ACM SIGCOMM 2000, Stockholm, Sweden, September 2000, pp. 163--74. Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. D.-F. Chang, R. Govindan, and J. Heidemann, "An empirical study of router response to large BGP routing table load," Tech. Rep. ISI-TR-2001-552, USC/Information Sciences Institute, December 2001.Google ScholarGoogle Scholar
  13. S. Ramachandra, Y. Rekhter, R. Fernando, J. Scudder, and E. Chen, "Graceful restart mechanism for BGP," lnternet Draft October 2000.Google ScholarGoogle Scholar
  14. University of Oregon, "The Route Views Project," http://www.antc.uoregon.edu/route-views/.Google ScholarGoogle Scholar

Index Terms

  1. Observation and analysis of BGP behavior under stress

        Recommendations

        Comments

        Login options

        Check if you have access through your login credentials or your institution to get full access on this article.

        Sign in
        • Published in

          cover image ACM Conferences
          IMW '02: Proceedings of the 2nd ACM SIGCOMM Workshop on Internet measurment
          November 2002
          334 pages
          ISBN:158113603X
          DOI:10.1145/637201

          Copyright © 2002 ACM

          Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

          Publisher

          Association for Computing Machinery

          New York, NY, United States

          Publication History

          • Published: 6 November 2002

          Permissions

          Request permissions about this article.

          Request Permissions

          Check for updates

          Qualifiers

          • Article

          Acceptance Rates

          Overall Acceptance Rate29of80submissions,36%

          Upcoming Conference

          IMC '24
          ACM Internet Measurement Conference
          November 4 - 6, 2024
          Madrid , AA , Spain

        PDF Format

        View or Download as a PDF file.

        PDF

        eReader

        View online with eReader.

        eReader