PathProb: Probabilistic Inference and Path Scoring for Enhanced and Flexible BGP Route Leak Detection
Yingqian Hao, Hui Zou, Lu Zhou, Yuxuan Chen, Yanbiao Li
Abstract
The Border Gateway Protocol (BGP) lacks inherent security, leaving the Internet vulnerable to severe threats like route leaks. Existing detection methods suffer from limitations such as rigid binary classification, high false positives, and sparse authoritative AS relationship data. To address these challenges, this paper proposes PathProb-a novel paradigm that flexibly identifies route leaks by calculating topology-aware probability distributions for AS links and computing legitimacy scores for AS paths. Our approach integrates Monte Carlo methods with an Integer Linear Programming formulation of routing policies to derive these solutions efficiently. We comprehensively evaluate PathProb using real-world BGP routing traces and route leak incidents. Results show our inference model outperforms state-of-the-art approaches with a high-confidence validation dataset. PathProb detects real-world route leaks with 98.45% recall while simultaneously reducing false positives by 4.29 ∼ 20.08 percentage points over stateof-the-art alternatives. Additionally, PathProb's path legitimacy scoring enables network administrators to dynamically adjust route leak detection thresholds-tailoring security posture to their specific false alarm tolerance and security needs. Finally, PathProb offers seamless compatibility with emerging route leak mitigation mechanisms, such as Autonomous System Provider Authorization (ASPA), enabling flexible integration to enhance leak detection capabilities. Role T1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3eaf25ad-4f0c-4a08-a722-ba1517fff1b7Builds on4
- Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection SystemYihao Chen, Qilei Yin, Qi Li, Zhuotao Liu et al.USENIX Security 2024 · 14 citations
- Flexsealing BGP Against Route Leaks: Peerlock Active Measurement and AnalysisTyler McDaniel, Jared M. Smith, Max SchuchardNDSS 2021
- BGP-iSec: Improved Security of Internet Routing Against Post-ROV AttacksCameron Morris, Amir Herzberg, Bing Wang, Samuel SecondoNDSS 2024
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya et al.NDSS 2025
Related papers
- Accurate and Stable AS Relationship Inference via Trusted Seeds and Semi-Supervised LearningSiyuan Teng, Lancheng Qin, Li Chen, Dan Li et al.INFOCOM 2026
- Ares: Comprehensive Path Hijacking Detection via Routing TreeYinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang et al.USENIX Security 2025
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti et al.NSDI 2024 · 21 citations
- Resolution Without Dissent: In-Path Per-Query Sanitization to Defeat Surreptitious Communication Over DNSDaiping Liu, Ruian Duan, Jun WangS&P 2025
- Which way to go? Inferring Fine-Grained AS Paths with PathRadarZitong Jin, Xingang Shi, Qiang Ma, Letong Sun et al.INFOCOM 2025 · 1 citation
