首页> 外文会议>International Workshop on Traffic Monitoring and Analysis >Investigating the Nature of Routing Anomalies: Closing in on Subprefix Hijacking Attacks
【24h】

Investigating the Nature of Routing Anomalies: Closing in on Subprefix Hijacking Attacks

机译:调查路由异常的性质:关闭子预先劫持攻击

获取原文

摘要

The detection of BGP hijacking attacks has been at the focus of research for more than a decade. However, state-of-the-art techniques fall short of detecting subprefix hijacking, where smaller parts of a victim's networks are targeted by an attacker. The analysis of corresponding routing anomalies, so-called subMOAS events, is tedious since these anomalies are numerous and mostly have legitimate reasons. In this paper, we propose, implement and test a new approach to investigate subMOAS events. Our method combines input from several data sources that can reliably disprove malicious intent. First, we make use of the database of a Internet Routing Registry (IRR) to derive business relations between the parties involved in a subMOAS event. Second, we use a topology-based reasoning algorithm to rule out subMOAS events caused by legitimate network setups. Finally, we use Internet-wide network scans to identify SSL-enabled hosts in a large number of subnets. Where we observe that public/private key pairs do not change during an event, we can eliminate the possibility of an attack. We can show that subprefix announcements with multiple origins are harmless for the largest part. This significantly reduces the search space in which we need to look for hijacking attacks.
机译:BGP劫持攻击的检测已经在研究的焦点上超过十年。然而,最先进的技术缺少检测子预劫持的次级资料,其中受害者网络的较小部分由攻击者为目标。分析相应的路由异常,所谓的潜水机构事件,因为这些异常是许多而且主要有合法原因。在本文中,我们建议,实施和测试一种调查潜水机构事件的新方法。我们的方法将来自几个数据源的输入组合可以可靠地反对恶意意图。首先,我们利用Internet路由注册表(IRR)的数据库,以导出潜水机构涉及的各方之间的业务关系。其次,我们使用基于拓扑的推理算法来排除由合法网络设置引起的潜水器事件。最后,我们使用Internet范围的网络扫描来识别大量子网中的启用SSL的主机。在我们观察到公共/私钥对在活动期间没有改变,我们可以消除攻击的可能性。我们可以表明具有多种起源的子预先子推销对最大部分无害。这显着减少了我们需要寻找劫持攻击的搜索空间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号