首页> 外文期刊>IEEE/ACM Transactions on Networking >The BGP Visibility Toolkit: Detecting Anomalous Internet Routing Behavior
【24h】

The BGP Visibility Toolkit: Detecting Anomalous Internet Routing Behavior

机译:BGP可见性工具包:检测Internet路由异常行为

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

In this paper, we propose the BGP Visibility Toolkit, a system for detecting and analyzing anomalous behavior in the Internet. We show that interdomain prefix visibility can be used to single out cases of erroneous demeanors resulting from misconfiguration or bogus routing policies. The implementation of routing policies with BGP is a complicated process, involving fine-tuning operations and interactions with the policies of the other active ASes. Network operators might end up with faulty configurations or unintended routing policies that prevent the success of their strategies and impact their revenues. As part of the Visibility Toolkit, we propose the BGP Visibility Scanner, a tool which identifies limited visibility prefixes in the Internet. The tool enables operators to provide feedback on the expected visibility status of prefixes. We build a unique set of ground-truth prefixes qualified by their ASes as intended or unintended to have limited visibility. Using a machine learning algorithm, we train on this unique dataset an alarm system that separates with 95% accuracy the prefixes with unintended limited visibility. Hence, we find that visibility features are generally powerful to detect prefixes which are suffering from inadvertent effects of routing policies. Limited visibility could render a whole prefix globally unreachable. This points towards a serious problem, as limited reachability of a non-negligible set of prefixes undermines the global connectivity of the Internet. We thus verify the correlation between global visibility and global connectivity of prefixes.
机译:在本文中,我们提出了BGP Visibility Toolkit,这是一个用于检测和分析Internet异常行为的系统。我们表明,域间前缀可见性可用于找出由于配置错误或虚假路由策略而导致行为举止错误的情况。使用BGP实施路由策略是一个复杂的过程,涉及到微调操作以及与其他活动AS的策略的交互。网络运营商最终可能会遇到错误的配置或意外的路由策略,从而阻碍其策略的成功并影响其收入。作为可见性工具包的一部分,我们提出了BGP可见性扫描程序,该工具可识别Internet中有限的可见性前缀。该工具使操作员能够提供有关前缀的预期可见性状态的反馈。我们构建了一组唯一的地面真实性前缀,这些前缀由其AS所限定,无论是有意还是无意的,它们的可见性均有限。通过使用机器学习算法,我们在此独特的数据集上训练了一个警报系统,该警报系统以95%的准确度分隔了具有意外限制的可见性的前缀。因此,我们发现可见性功能通常可强大地检测受到路由策略的无意影响的前缀。有限的可见性可能会使整个前缀在全球范围内无法访问。这指出了一个严重的问题,因为一组不可忽略的前缀的有限可达性破坏了Internet的全局连接性。因此,我们验证了全局可见性和前缀的全局连通性之间的相关性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号