Nothing Special   »   [go: up one dir, main page]

skip to main content
10.1109/ICNP.2012.6459962guideproceedingsArticle/Chapter ViewAbstractPublication PagesConference Proceedingsacm-pubtype
Article

Buddyguard: A buddy system for fast and reliable detection of IP prefix anomalies

Published: 30 October 2012 Publication History

Abstract

Due to operational malpractice or security attacks, an IP prefix (i.e., a block of IP addresses) can undergo many types of routing anomalies. Perhaps the most well-known of such anomalies is prefix hijacking, where an attacker hijacks traffic meant to reach the legitimate user of a prefix. Anomalies can also easily occur through route leaks, which can disrupt traffic for numerous prefixes at once. While various solutions have been proposed to detect such anomalies, these solutions are limited and susceptible to attacker countermeasures. In this paper we present Buddyguard, a new approach to detecting prefix anomalies including prefix hijacking and route leaks. Buddyguard compares the behavior of a monitored prefix with the behavior of a set of numerous buddy prefixes. The system detects anomalies when the behavior of the monitored prefix significantly diverges from that of its buddies. Our evaluation results show that Buddyguard provides fast, accurate and lightweight monitoring of IP prefix anomalies, and its introduction and use of buddy prefixes enables it to be resilient against resourceful attackers.

Cited By

View all
  • (2016)Jumpstarting BGP Security with Path-End ValidationProceedings of the 2016 ACM SIGCOMM Conference10.1145/2934872.2934883(342-355)Online publication date: 22-Aug-2016
  • (2014)Towards detecting target link flooding attackProceedings of the 28th USENIX conference on Large Installation System Administration10.5555/2717491.2717497(81-96)Online publication date: 9-Nov-2014

Index Terms

  1. Buddyguard: A buddy system for fast and reliable detection of IP prefix anomalies
      Index terms have been assigned to the content through auto-classification.

      Recommendations

      Comments

      Please enable JavaScript to view thecomments powered by Disqus.

      Information & Contributors

      Information

      Published In

      cover image Guide Proceedings
      ICNP '12: Proceedings of the 2012 20th IEEE International Conference on Network Protocols (ICNP)
      October 2012
      403 pages
      ISBN:9781467324458

      Publisher

      IEEE Computer Society

      United States

      Publication History

      Published: 30 October 2012

      Author Tags

      1. IP networks
      2. Monitoring

      Qualifiers

      • Article

      Contributors

      Other Metrics

      Bibliometrics & Citations

      Bibliometrics

      Article Metrics

      • Downloads (Last 12 months)0
      • Downloads (Last 6 weeks)0
      Reflects downloads up to 22 Sep 2024

      Other Metrics

      Citations

      Cited By

      View all
      • (2016)Jumpstarting BGP Security with Path-End ValidationProceedings of the 2016 ACM SIGCOMM Conference10.1145/2934872.2934883(342-355)Online publication date: 22-Aug-2016
      • (2014)Towards detecting target link flooding attackProceedings of the 28th USENIX conference on Large Installation System Administration10.5555/2717491.2717497(81-96)Online publication date: 9-Nov-2014

      View Options

      View options

      Get Access

      Login options

      Media

      Figures

      Other

      Tables

      Share

      Share

      Share this Publication link

      Share on social media