USENIX Security2025Top-tier venue
Ares: Comprehensive Path Hijacking Detection via Routing Tree
Yinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang, Jilong Wang, Congcong Miao
Abstract
Since Border Gateway Protocol (BGP) lacks a strong security mechanism, prefix hijacking attacks are becoming increasingly rampant, which has drawn a lot of attention from both academia and industry. Recently, prefix hijacking has evolved from origin hijacking to more stealthy hijacking, i.e., path hijacking, to bypass existing hijacking detection systems. The attacker will manipulate the AS path attributes while announcing the prefix of the victim AS. However, existing systems only target origin hijacking or only address part of the path hijacking, which allows attackers to exploit vulnerabilities to hijack. In this paper, our observation shows that path hijacking triggers the creation of a new observed prefix's routing tree (OPRT) within an AS and we advocate for a radical new approach to comprehensively address all types of path hijacking. We propose a first-of-its-kind system, called Ares, to detect path hijacking in an effective, accurate, and fast way. At the core of Ares is weighted edit distance to quantify the differences between routing trees, combined with a clustering mechanism to accelerate anomaly detection and heuristic rules to further increase the detection accuracy. We validate Ares with historical hijacking events and large-scale simulations, For each of the 12 real-world events, Ares was able to detect the hijacking within 5 minutes of its occurrence. Additionally, simulations show that Ares detects an average of 97.2% and 99.3% of stealthy exact and sub-prefix path hijackings targeting Tier-1 and content ASes with only 1.06% of false positive rate, outperforming state-of-the-art methods. In addition, it generates only 2.31 suspicious alerts per hour across the entire Internet, a manageable volume for operators to investigate and respond effectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4f008796-d325-42c5-bd7d-b437048f5ca4Builds on2
- Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection SystemYihao Chen, Qilei Yin, Qi Li, Zhuotao Liu et al.USENIX Security 2024 · 14 citations
- Themis: Accelerating the Detection of Route Origin Hijacking by Distinguishing Legitimate and Illegitimate MOASLancheng Qin, Dan Li, Ruifeng Li, Kang WangUSENIX Security 2022
Related papers
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti et al.NSDI 2024 · 21 citations
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya et al.NDSS 2025
- Counter-RAPTOR: Safeguarding Tor Against Active Routing AttacksYixin Sun, Anne Edmundson, Nick Feamster, Mung Chiang et al.S&P 2017 · 60 citations
- Understanding the Stealthy BGP Hijacking Risk in the ROV EraYihao Chen, Qi Li, Ke Xu, Zhuotao Liu et al.NDSS 2026
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
