Netinfo Security ›› 2019, Vol. 19 ›› Issue (11): 63-70.doi: 10.3969/j.issn.1671-1122.2019.11.009

Previous Articles     Next Articles

Research on Inter-domain Routing Anomaly Detection Technology

Hailian DENG1, Yujing LIU1(), Yixuan GE2, Jinshu SU1   

  1. 1. College of Computer Science and Technology, National University of Defense Technology, Changsha Hunan 410005, China
    2. College of Liberal Arts and Sciences, National University of Defense Technology,Changsha Hunan 410005, China
  • Received:2019-07-17 Online:2019-11-10 Published:2020-05-11

Abstract:

Due to the shortcomings of BGP protocol design, the inter-domain routing system suffers serious security problems such as prefix hijacking, path tampering and route leakage. Currently, the related routing anomaly detection systems usually use the abnormal characteristics of routing message and data traffic to detect. However, due to the instantaneous change of network environment and the variety of routing attacks, it is difficult to locate abnormal events effectively and accurately. This paper analyzes the massive real inter-domain routing data and finds that the routing changes show power law, that is, the routing between the vast majority of source target pairs is stable, and the routing between a few source target pairs will change frequently. Based on the observation results, this paper proposes a detection method of detecting abnormal routing behavior by comparing the deviation of routing behavior from the normal model, and tests and verifies the real hijacking of Japanese network events on the Internet. This method can provide powerful support for the detection and analysis of routing abnormal events, and is of great significance for improving the rapid response of abnormal events.

Key words: inter-domain routing, anomaly detection, BGP

CLC Number: