A Survey of Advanced Border Gateway Protocol Attack Detection Techniques

被引:2
|
作者
Scott, Ben A. [1 ,2 ]
Johnstone, Michael N. [1 ]
Szewczyk, Patryk [1 ]
机构
[1] Edith Cowan Univ, Sch Sci, Perth, WA 6027, Australia
[2] RMIT Univ, Sch Sci Engn & Technol, Ho Chi Minh City 700000, Vietnam
关键词
anomaly detection; BGP; cyber security; Internet security; routing security; TIME-SERIES DATA; ANOMALY DETECTION; FRAMEWORK; SCALE; ALGORITHM; DESIGN; SCHEME;
D O I
10.3390/s24196414
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The Internet's default inter-domain routing system, the Border Gateway Protocol (BGP), remains insecure. Detection techniques are dominated by approaches that involve large numbers of features, parameters, domain-specific tuning, and training, often contributing to an unacceptable computational cost. Efforts to detect anomalous activity in the BGP have been almost exclusively focused on single observable monitoring points and Autonomous Systems (ASs). BGP attacks can exploit and evade these limitations. In this paper, we review and evaluate categories of BGP attacks based on their complexity. Previously identified next-generation BGP detection techniques remain incapable of detecting advanced attacks that exploit single observable detection approaches and those designed to evade public routing monitor infrastructures. Advanced BGP attack detection requires lightweight, rapid capabilities with the capacity to quantify group-level multi-viewpoint interactions, dynamics, and information. We term this approach advanced BGP anomaly detection. This survey evaluates 178 anomaly detection techniques and identifies which are candidates for advanced attack anomaly detection. Preliminary findings from an exploratory investigation of advanced BGP attack candidates are also reported.
引用
收藏
页数:44
相关论文
共 50 条
  • [31] Border gateway protocol monitoring system can be cost effective
    Chen, K.
    Hu, C.
    IET COMMUNICATIONS, 2011, 5 (15) : 2231 - 2240
  • [32] Enhancing Border Gateway Protocol Security Using Public Blockchain
    Mastilak, Lukas
    Galinski, Marek
    Helebrandt, Pavol
    Kotuliak, Ivan
    Ries, Michal
    SENSORS, 2020, 20 (16) : 1 - 11
  • [33] A Parallel Processing Method for Border Gateway Protocol UPDATE Messages
    Ding, Lina
    Wang, Xingwei
    Li, Fuliang
    Huang, Min
    2015 12th International Conference on Fuzzy Systems and Knowledge Discovery (FSKD), 2015, : 2044 - 2048
  • [34] An Analytical Survey of State of the Art JellyFish Attack Detection and Prevention Techniques
    Garg, Anjani
    Kumar, Sunil
    Dutta, Kamlesh
    2016 FOURTH INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (PDGC), 2016, : 38 - 43
  • [35] A Contemporary Survey of Multimodal Presentation Attack Detection Techniques: Challenges and Opportunities
    Kavita
    Walia G.S.
    Rohilla R.
    SN Computer Science, 2021, 2 (1)
  • [36] Detection Techniques of Blackhole Attack in Mobile Adhoc Network- A Survey
    Jain, Sakshi
    Khunteta, Ajay
    ICARCSET'15: PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON ADVANCED RESEARCH IN COMPUTER SCIENCE ENGINEERING & TECHNOLOGY (ICARCSET - 2015), 2015,
  • [37] Border gateway protocol graph: detecting and visualising internet routing anomalies
    Papadopoulos, Stavros
    Moustakas, Konstantinos
    Drosou, Anastasios
    Tzovaras, Dimitrios
    IET INFORMATION SECURITY, 2016, 10 (03) : 125 - 133
  • [38] Route Advertisement Policies for Border Gateway Protocol with Provider Aggregatable Addressing
    Al Muktadir, Abu Hena
    Fujikawa, Kenji
    Harai, Hiroaki
    2016 IEEE 17TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (HPSR), 2016, : 42 - 48
  • [39] ANTITRUST ANALYSIS FOR THE INTERNET UPSTREAM MARKET: A BORDER GATEWAY PROTOCOL APPROACH
    D'Ignazio, Alessio
    Giovannetti, Emanuele
    JOURNAL OF COMPETITION LAW & ECONOMICS, 2006, 2 (01) : 43 - 69
  • [40] An improved energy efficient quality of service routing for border gateway protocol
    Shukla, Shipra
    Kumar, Mahesh
    COMPUTERS & ELECTRICAL ENGINEERING, 2018, 67 : 520 - 535