BGPFuzz: Automated Configuration Fuzzing of the Border Gateway Protocol

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Chenlu, Pasdar, Amirmohammad, Pham, Van-Thuan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909945729908736
author Zhang, Chenlu
Pasdar, Amirmohammad
Pham, Van-Thuan
author_facet Zhang, Chenlu
Pasdar, Amirmohammad
Pham, Van-Thuan
contents Telecommunications networks rely on configurations to define routing behavior, especially in the Border Gateway Protocol (BGP), where misconfigurations can lead to severe outages and security breaches, as demonstrated by the 2021 Facebook outage. Unlike existing approaches that rely on synthesis or verification, our work offers a cost-effective method for identifying misconfigurations resulting from BGP's inherent complexity or vendor-specific implementations. We present BGPFuzz, a structure-aware and stateful fuzzing framework that systematically mutates BGP configurations and evaluates their effects in virtualized network. Without requiring predefined correctness properties as in static analysis, BGPFuzz detects anomalies through runtime oracles that capture practical symptoms such as session resets, blackholing, and traffic redirection. Our experiments show that BGPFuzz can reliably reproduce and detect known failures, including max-prefix violations and sub-prefix hijacks.
format Preprint
id arxiv_https___arxiv_org_abs_2512_05358
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle BGPFuzz: Automated Configuration Fuzzing of the Border Gateway Protocol
Zhang, Chenlu
Pasdar, Amirmohammad
Pham, Van-Thuan
Software Engineering
Telecommunications networks rely on configurations to define routing behavior, especially in the Border Gateway Protocol (BGP), where misconfigurations can lead to severe outages and security breaches, as demonstrated by the 2021 Facebook outage. Unlike existing approaches that rely on synthesis or verification, our work offers a cost-effective method for identifying misconfigurations resulting from BGP's inherent complexity or vendor-specific implementations. We present BGPFuzz, a structure-aware and stateful fuzzing framework that systematically mutates BGP configurations and evaluates their effects in virtualized network. Without requiring predefined correctness properties as in static analysis, BGPFuzz detects anomalies through runtime oracles that capture practical symptoms such as session resets, blackholing, and traffic redirection. Our experiments show that BGPFuzz can reliably reproduce and detect known failures, including max-prefix violations and sub-prefix hijacks.
title BGPFuzz: Automated Configuration Fuzzing of the Border Gateway Protocol
topic Software Engineering
url https://arxiv.org/abs/2512.05358