USENIX Security2022Top-tier venue
Themis: Accelerating the Detection of Route Origin Hijacking by Distinguishing Legitimate and Illegitimate MOAS
Lancheng Qin, Dan Li, Ruifeng Li, Kang Wang
Abstract
Route hijacking is one of the most severe security problems in today's Internet, and route origin hijacking is the most common. While origin hijacking detection systems are already available, they suffer from tremendous pressures brought by frequent legitimate Multiple origin ASes (MOAS) conflicts. They detect MOAS conflicts on the control plane and then identify origin hijackings by data-plane probing or even manual verification. However, legitimate changes in prefix ownership can also cause MOAS conflicts, which are the majority of MOAS conflicts daily. Massive legitimate MOAS conflicts consume many resources for probing and identification, resulting in high verification costs and high verification latency in practice. In this paper, we propose a new origin hijacking system T hemis to accelerate the detection of origin hijacking. Based on the ground truth dataset we built, we analyze the characteristics of different MOAS conflicts and train a classifier to filter out legitimate MOAS conflicts on the control plane. The accuracy and recall of the MOAS classifier are 95.49% and 99.20%, respectively. Using the MOAS classifier, T hemis reduces 56.69% of verification costs than Argus, the state-of-the-art, and significantly accelerates the detection when many concurrent MOAS conflicts occur. The overall accuracy of T hemis is almost the same as Argus.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 140eba38-7c04-4c95-868f-e8297fa4e388Cited by top-tier papers8
- The Next Generation of BGP Data Collection PlatformsThomas Alfroy, Thomas Holterbach, Thomas Krenc, K. C. Claffy et al.SIGCOMM 2024 · 20 citations
- OSAVRoute: Advancing Outbound Source Address Validation Deployment Detection with Non-Cooperative MeasurementShuai Wang, Ruifeng Li, Li Chen, Dan Li et al.NDSS 2026 · 3 citations
- Ares: Comprehensive Path Hijacking Detection via Routing TreeYinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang et al.USENIX Security 2025
- The Threat Landscape of IP Leasing in the RPKI EraWeitong Li, Yongzhe Xu, Taejoong ChungS&P 2026
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
Builds on1
Related papers
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti et al.NSDI 2024 · 21 citations
- Understanding Route Origin Validation (ROV) Deployment in the Real World and Why MANRS Action 1 Is Not FollowedLancheng Qin, Li Chen, Dan Li, Honglin Ye et al.NDSS 2024
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
- Understanding the Stealthy BGP Hijacking Risk in the ROV EraYihao Chen, Qi Li, Ke Xu, Zhuotao Liu et al.NDSS 2026
- DISCO: Sidestepping RPKI's Deployment BarriersTomas Hlavacek, Ítalo Cunha, Yossi Gilad, Amir Herzberg et al.NDSS 2020
