Accurate real-time identification of IP prefix hijacking

被引:76
|
作者
Hu, Xin [1 ]
Mao, Z. Morley [1 ]
机构
[1] Univ Michigan, Ann Arbor, MI 48109 USA
关键词
D O I
10.1109/SP.2007.7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present novel and practical techniques to accurately detect IP prefix hijacking attacks in real time to facilitate mitigation. Attacks may hijack victim's address space to disrupt network services or perpetrate malicious activities such as spamming and DoS attacks without disclosing identity. We propose novel ways to significantly improve the detection accuracy by combining analysis of passively collected BGP routing updates with data plane fingerprints of suspicious prefixes. The key insight is to use data plane information in the form of edge network fingerprinting to disambiguate suspect IP hijacking incidences based on routing anomaly detection. Conflicts in data plane fingerprints provide much more definitive evidence of successful IP prefix hijacking. Utilizing multiple real-time BGP feeds, we demonstrate the ability of our system to distinguish between legitimate routing changes and actual attacks. Strong correlation with addresses that originate spam emails from a spam honeypot confirms the accuracy of our techniques.
引用
收藏
页码:3 / +
页数:3
相关论文
共 50 条
  • [31] A performance study on real-time IP multicasting
    Demirci, T
    Bilgen, S
    [J]. EIGHTH IEEE INTERNATIONAL SYMPOSIUM ON COMPUTERS AND COMMUNICATION, VOLS I AND II, PROCEEDINGS, 2003, : 441 - 446
  • [32] IP Agnostic Real-Time Traffic Filtering and Host Identification Using TCP Timestamps
    Wicherski, Georg
    Weingarten, Florian
    Meyer, Ulrike
    [J]. PROCEEDINGS OF THE 2013 38TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2013), 2013, : 647 - 654
  • [33] Real-time fingerprint identification
    Alm, MS
    Akhteruzzaman, M
    Cherrri, AK
    [J]. OPTICS AND LASER TECHNOLOGY, 2004, 36 (03): : 191 - 196
  • [34] Real-time publish-subscribe protocol for IP-based real-time communication
    Pardo-Castellote, G
    Ssonck, S
    Hamilton, M
    Choi, H
    [J]. INSTRUMENTATION, SYSTEMS, AND AUTOMATION CONFERENCE PROCEEDINGS, 2002, 434 : 271 - 281
  • [35] Fast, accurate, and lightweight real-time traffic identification method based on flow statistics
    Tai, Masaki
    Ata, Shingo
    Oka, Ikuo
    [J]. PASSIVE AND ACTIVE NETWORK MEASUREMENT, PROCEEDINGS, 2007, 4427 : 255 - +
  • [36] Real-Time Learning of Accurate Patch Rectification
    Hinterstoisser, Stefan
    Kutter, Oliver
    Navab, Nassir
    Fua, Pascal
    Lepetit, Vincent
    [J]. CVPR: 2009 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, VOLS 1-4, 2009, : 2937 - +
  • [37] Real-Time Accurate Assessment of Insulin Sensitivity
    Docherty, Paul D.
    Chase, J. Geoffrey
    Lotz, Thomas
    Hann, Christopher E.
    Shaw, Geoffrey M.
    Berkeley, Juliet
    McAuley, Kirsten
    Mann, Jim I.
    [J]. DIABETES, 2009, 58 : A542 - A543
  • [38] Accurate, real-time, unadorned lip tracking
    Kaucic, R
    Blake, A
    [J]. SIXTH INTERNATIONAL CONFERENCE ON COMPUTER VISION, 1998, : 370 - 375
  • [39] Accurate Real-time Occlusion for Mixed Reality
    Walton, David R.
    Steed, Anthony
    [J]. VRST'17: PROCEEDINGS OF THE 23RD ACM SYMPOSIUM ON VIRTUAL REALITY SOFTWARE AND TECHNOLOGY, 2017,
  • [40] ArduSim: Accurate and real-time multicopter simulation
    Fabra, Francisco
    Calafate, Carlos T.
    Carlos Cano, Juan
    Manzoni, Pietro
    [J]. SIMULATION MODELLING PRACTICE AND THEORY, 2018, 87 : 170 - 190