Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection System

被引:0
|
作者
Chen, Yihao [1 ,2 ]
Yin, Qilei [3 ]
Li, Qi [3 ,4 ]
Liu, Zhuotao [3 ,4 ]
Xu, Ke [3 ,5 ]
Xu, Yi [3 ,4 ]
Xu, Mingwei [3 ,4 ]
Liu, Ziqian [6 ]
Wu, Jianping [3 ,5 ]
机构
[1] Tsinghua Univ, Dept Comp Sci & Technol, Beijing, Peoples R China
[2] Tsinghua Univ, BNRist, Beijing, Peoples R China
[3] Zhongguancun Lab, Beijing, Peoples R China
[4] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing, Peoples R China
[5] Tsinghua Univ, Dept Comp Sci & Technol, Beijing, Peoples R China
[6] China Telecom, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
PREFIX HIJACKING;
D O I
暂无
中图分类号
学科分类号
摘要
BGP is the de facto inter-domain routing protocol to ensure global connectivity of the Internet. However, various reasons, such as deliberate attacks or misconfigurations, could cause BGP routing anomalies. Traditional methods for BGP routing anomaly detection require significant manual investigation of routes by network operators. Although machine learning has been applied to automate the process, prior arts typically impose significant training overhead (such as large-scale data labeling and feature crafting), and only produce uninterpretable results. To address these limitations, this paper presents a routing anomaly detection system centering around a novel network representation learning model named BEAM. The core design of BEAM is to accurately learn the unique properties (defined as routing role) of each Autonomous System (AS) in the Internet by incorporating BGP semantics. As a result, routing anomaly detection, given BEAM, is reduced to a matter of discovering unexpected routing role churns upon observing new route announcements. We implement a prototype of our routing anomaly detection system and extensively evaluate its performance. The experimental results, based on 18 real-world RouteViews datasets containing over 11 billion route announcement records, demonstrate that our system can detect all previously-confirmed routing anomalies, while only introducing at most five false alarms every 180 million route announcements. We also deploy our system at a large ISP to perform real-world detection for one month. During the course of deployment, our system detects 497 true anomalies in the wild with an average of only 1.65 false alarms per day.
引用
收藏
页码:5143 / 5160
页数:18
相关论文
共 50 条
  • [21] Semantics-Aware Machine Learning for Function Recognition in Binary Code
    Wang, Shuai
    Wang, Pei
    Wu, Dinghao
    2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME), 2017, : 388 - 398
  • [22] Technical Perspective BLeak: Semantics-Aware Leak Detection in the Web
    Xu, Harry
    COMMUNICATIONS OF THE ACM, 2020, 63 (11) : 145 - 145
  • [23] Learning Semantics-Aware Locomotion Skills from Human Demonstration
    Yang, Yuxiang
    Meng, Xiangyun
    Yu, Wenhao
    Zhang, Tingnan
    Tan, Jie
    Boots, Byron
    CONFERENCE ON ROBOT LEARNING, VOL 205, 2022, 205 : 2205 - 2214
  • [24] An Intelligent and Semantics-Aware Distraction-Free Writing System
    Johannsen, Jonathan
    Sun, Yu
    2017 11TH IEEE INTERNATIONAL CONFERENCE ON SEMANTIC COMPUTING (ICSC), 2017, : 465 - 468
  • [25] Towards Robust Text Classification with Semantics-Aware Recurrent Neural Architecture
    Skrlj, Blaz
    Kralj, Jan
    Lavrac, Nada
    Pollak, Senja
    MACHINE LEARNING AND KNOWLEDGE EXTRACTION, 2019, 1 (02):
  • [26] System Description: A Semantics-Aware LATEX-to-Office Converter
    Kohlhase, Lukas
    Kohlhase, Michael
    INTELLIGENT COMPUTER MATHEMATICS, CICM 2014, 2014, 8543 : 440 - 443
  • [27] Enforcing semantics-aware security in multimedia surveillance
    Kodali, N
    Farkas, C
    Wijesekera, D
    JOURNAL ON DATA SEMANTICS II, 2005, 3360 : 199 - 221
  • [28] Learning to Make Better Mistakes: Semantics-aware Visual Food Recognition
    Wu, Hui
    Merler, Michele
    Uceda-Sosa, Rosario
    Smith, John R.
    MM'16: PROCEEDINGS OF THE 2016 ACM MULTIMEDIA CONFERENCE, 2016, : 172 - 176
  • [29] LAIR: A Language for Automated Semantics-Aware Text Sanitization based on Frame Semantics
    Hedegaard, Steffen
    Houen, Soren
    Simonsen, Jakob Grue
    2009 IEEE THIRD INTERNATIONAL CONFERENCE ON SEMANTIC COMPUTING (ICSC 2009), 2009, : 47 - 52
  • [30] Semantics-aware Exploration and Inspection Path Planning
    Dharmadhikari, Mihir
    Alexis, Kostas
    2023 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION, ICRA, 2023, : 3360 - 3367