Is Crunching Public Data the Right Approach to Detect BGP Hijacks?

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Giaconia, Alessandro, Tran, Muoi, Vanbever, Laurent, Vissicchio, Stefano
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913962107338752
author Giaconia, Alessandro
Tran, Muoi
Vanbever, Laurent
Vissicchio, Stefano
author_facet Giaconia, Alessandro
Tran, Muoi
Vanbever, Laurent
Vissicchio, Stefano
contents The Border Gateway Protocol (BGP) remains a fragile pillar of Internet routing. BGP hijacks still occurr daily. While full deployment of Route Origin Validation (ROV) is ongoing, attackers have already adapted, launching post-ROV attacks such as forged-origin hijacks. To detect these, recent approaches like DFOH [Holterbach et al., USENIX NSDI '24] and BEAM [Chen et al., USENIX Security '24] apply machine learning (ML) to analyze data from globally distributed BGP monitors, assuming anomalies will stand out against historical patterns. However, this assumption overlooks a key threat: BGP monitors themselves can be misled by adversaries injecting bogus routes. This paper shows that state-of-the-art hijack detection systems like DFOH and BEAM are vulnerable to data poisoning. Using large-scale BGP simulations, we show that attackers can evade detection with just a handful of crafted announcements beyond the actual hijack. These announcements are indeed sufficient to corrupt the knowledge base used by ML-based defenses and distort the metrics they rely on. Our results highlight a worrying weakness of relying solely on public BGP data.
format Preprint
id arxiv_https___arxiv_org_abs_2507_20434
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Is Crunching Public Data the Right Approach to Detect BGP Hijacks?
Giaconia, Alessandro
Tran, Muoi
Vanbever, Laurent
Vissicchio, Stefano
Cryptography and Security
Networking and Internet Architecture
The Border Gateway Protocol (BGP) remains a fragile pillar of Internet routing. BGP hijacks still occurr daily. While full deployment of Route Origin Validation (ROV) is ongoing, attackers have already adapted, launching post-ROV attacks such as forged-origin hijacks. To detect these, recent approaches like DFOH [Holterbach et al., USENIX NSDI '24] and BEAM [Chen et al., USENIX Security '24] apply machine learning (ML) to analyze data from globally distributed BGP monitors, assuming anomalies will stand out against historical patterns. However, this assumption overlooks a key threat: BGP monitors themselves can be misled by adversaries injecting bogus routes. This paper shows that state-of-the-art hijack detection systems like DFOH and BEAM are vulnerable to data poisoning. Using large-scale BGP simulations, we show that attackers can evade detection with just a handful of crafted announcements beyond the actual hijack. These announcements are indeed sufficient to corrupt the knowledge base used by ML-based defenses and distort the metrics they rely on. Our results highlight a worrying weakness of relying solely on public BGP data.
title Is Crunching Public Data the Right Approach to Detect BGP Hijacks?
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2507.20434