Data-Plane Telemetry to Mitigate Long-Distance BGP Hijacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sengupta, Satadal, Kim, Hyojoon, Jubas, Daniel, Apostolaki, Maria, Rexford, Jennifer
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908457159884800
author Sengupta, Satadal
Kim, Hyojoon
Jubas, Daniel
Apostolaki, Maria
Rexford, Jennifer
author_facet Sengupta, Satadal
Kim, Hyojoon
Jubas, Daniel
Apostolaki, Maria
Rexford, Jennifer
contents Poor security of Internet routing enables adversaries to divert user data through unintended infrastructures (hijack). Of particular concern -- and the focus of this paper -- are cases where attackers reroute domestic traffic through foreign countries, exposing it to surveillance, bypassing legal privacy protections, and posing national security threats. Efforts to detect and mitigate such attacks have focused primarily on the control plane while data-plane signals remain largely overlooked. In particular, change in propagation delay caused by rerouting offers a promising signal: the change is unavoidable and the increased propagation delay is directly observable from the affected networks. In this paper, we explore the practicality of using delay variations for hijack detection, addressing two key questions: (1) What coverage can this provide, given its heavy dependence on the geolocations of the sender, receiver, and adversary? and (2) Can an always-on latency-based detection system be deployed without disrupting normal network operations? We observe that for 86% of victim-attacker country pairs in the world, mid-attack delays exceed pre-attack delays by at least 25% in real deployments, making delay-based hijack detection promising. To demonstrate practicality, we design HiDe, which reliably detects delay surges from long-distance hijacks at line rate. We measure HiDe's accuracy and false-positive rate on real-world data and validate it with ethically conducted hijacks.
format Preprint
id arxiv_https___arxiv_org_abs_2507_14842
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Data-Plane Telemetry to Mitigate Long-Distance BGP Hijacks
Sengupta, Satadal
Kim, Hyojoon
Jubas, Daniel
Apostolaki, Maria
Rexford, Jennifer
Networking and Internet Architecture
Poor security of Internet routing enables adversaries to divert user data through unintended infrastructures (hijack). Of particular concern -- and the focus of this paper -- are cases where attackers reroute domestic traffic through foreign countries, exposing it to surveillance, bypassing legal privacy protections, and posing national security threats. Efforts to detect and mitigate such attacks have focused primarily on the control plane while data-plane signals remain largely overlooked. In particular, change in propagation delay caused by rerouting offers a promising signal: the change is unavoidable and the increased propagation delay is directly observable from the affected networks. In this paper, we explore the practicality of using delay variations for hijack detection, addressing two key questions: (1) What coverage can this provide, given its heavy dependence on the geolocations of the sender, receiver, and adversary? and (2) Can an always-on latency-based detection system be deployed without disrupting normal network operations? We observe that for 86% of victim-attacker country pairs in the world, mid-attack delays exceed pre-attack delays by at least 25% in real deployments, making delay-based hijack detection promising. To demonstrate practicality, we design HiDe, which reliably detects delay surges from long-distance hijacks at line rate. We measure HiDe's accuracy and false-positive rate on real-world data and validate it with ethically conducted hijacks.
title Data-Plane Telemetry to Mitigate Long-Distance BGP Hijacks
topic Networking and Internet Architecture
url https://arxiv.org/abs/2507.14842