Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection System

被引:0
|
作者
Chen, Yihao [1 ,2 ]
Yin, Qilei [3 ]
Li, Qi [3 ,4 ]
Liu, Zhuotao [3 ,4 ]
Xu, Ke [3 ,5 ]
Xu, Yi [3 ,4 ]
Xu, Mingwei [3 ,4 ]
Liu, Ziqian [6 ]
Wu, Jianping [3 ,5 ]
机构
[1] Tsinghua Univ, Dept Comp Sci & Technol, Beijing, Peoples R China
[2] Tsinghua Univ, BNRist, Beijing, Peoples R China
[3] Zhongguancun Lab, Beijing, Peoples R China
[4] Tsinghua Univ, Inst Network Sci & Cyberspace, Beijing, Peoples R China
[5] Tsinghua Univ, Dept Comp Sci & Technol, Beijing, Peoples R China
[6] China Telecom, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
PREFIX HIJACKING;
D O I
暂无
中图分类号
学科分类号
摘要
BGP is the de facto inter-domain routing protocol to ensure global connectivity of the Internet. However, various reasons, such as deliberate attacks or misconfigurations, could cause BGP routing anomalies. Traditional methods for BGP routing anomaly detection require significant manual investigation of routes by network operators. Although machine learning has been applied to automate the process, prior arts typically impose significant training overhead (such as large-scale data labeling and feature crafting), and only produce uninterpretable results. To address these limitations, this paper presents a routing anomaly detection system centering around a novel network representation learning model named BEAM. The core design of BEAM is to accurately learn the unique properties (defined as routing role) of each Autonomous System (AS) in the Internet by incorporating BGP semantics. As a result, routing anomaly detection, given BEAM, is reduced to a matter of discovering unexpected routing role churns upon observing new route announcements. We implement a prototype of our routing anomaly detection system and extensively evaluate its performance. The experimental results, based on 18 real-world RouteViews datasets containing over 11 billion route announcement records, demonstrate that our system can detect all previously-confirmed routing anomalies, while only introducing at most five false alarms every 180 million route announcements. We also deploy our system at a large ISP to perform real-world detection for one month. During the course of deployment, our system detects 497 true anomalies in the wild with an average of only 1.65 false alarms per day.
引用
收藏
页码:5143 / 5160
页数:18
相关论文
共 50 条
  • [31] Semantics-Aware Scheduling Policies for Synchronization Determinism
    Zhao, Qi
    Qiu, Zhengyi
    Jin, Guoliang
    PROCEEDINGS OF THE 24TH SYMPOSIUM ON PRINCIPLES AND PRACTICE OF PARALLEL PROGRAMMING (PPOPP '19), 2019, : 242 - 256
  • [32] Semantics-aware services for the mobile computing environment
    Georgantas, N
    Ben Mokhtar, S
    Tartanoglu, F
    Issarny, V
    ARCHITECTING DEPENDABLE SYSTEMS III, 2005, 3549 : 1 - 35
  • [33] A Semantics-Aware Approach to Automated Claim Verification
    Figueras, Blanca Calvo
    Cuadros, Montse
    Agerri, Rodrigo
    PROCEEDINGS OF THE FIFTH FACT EXTRACTION AND VERIFICATION WORKSHOP (FEVER 2022), 2022, : 37 - 48
  • [34] Semantics-aware obfuscation scheme prediction for binary
    Zhao, Yujie
    Tang, Zhanyong
    Ye, Guixin
    Peng, Dongxu
    Fang, Dingyi
    Chen, Xiaojiang
    Wang, Zheng
    COMPUTERS & SECURITY, 2020, 99
  • [35] Semantics-aware influence maximization in social networks
    Chen, Yipeng
    Qu, Qiang
    Ying, Yuanxiang
    Li, Hongyan
    Shen, Jialie
    INFORMATION SCIENCES, 2020, 513 : 442 - 464
  • [36] Special issue - Semantics-aware techniques for security
    Damiani, E
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2004, 19 (03): : 119 - 120
  • [37] MinerRay: Semantics-Aware Analysis for Ever-Evolving Cryptojacking Detection
    Romano, Alan
    Zheng, Yunhui
    Wang, Weihang
    2020 35TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE 2020), 2020, : 1129 - 1140
  • [38] Semantics-aware data integration for heterogeneous data sources
    Leida, Marcello
    Gusmini, Alex
    Davies, John
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2013, 4 (04) : 471 - 491
  • [39] Extending context descriptions in semantics-aware Access Control
    Damiani, E.
    di Vimercati, S. De Capitani
    Fugazza, C.
    Samarati, P.
    INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2006, 4332 : 162 - +
  • [40] A Process Framework for Semantics-Aware Tourism Information Systems
    Daramola, Olawande J.
    CURRENT TRENDS IN WEB ENGINEERING, 2010, 6385s : 521 - 532