A System to Detect Forged-Origin BGP Hijacks
Thomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti, Cristel Pelsser
Abstract
Despite global efforts to secure Internet routing, attackers still successfully exploit the lack of strong BGP security mechanisms. This paper focuses on an attack vector that is frequently used: Forged-origin hijacks, a type of BGP hijack where the attacker manipulates the AS path to make it immune to RPKI-ROV filters and appear as legitimate routing updates from a BGP monitoring standpoint. Our contribution is DFOH, a system that quickly and consistently detects forgedorigin hijacks in the whole Internet. Detecting forged-origin hijacks boils down to inferring whether the AS path in a BGP route is legitimate or has been manipulated. We demonstrate that current state-of-art approaches to detect BGP anomalies are insufficient to deal with forged-origin hijacks. We identify the key properties that make the inference of forged AS paths challenging, and design DFOH to be robust against real-world factors (e.g., data biases). Our inference pipeline includes two key ingredients: (i) a set of strategically selected features, and (ii) a training scheme adapted to topological biases. DFOH detects 90.9% of the forged-origin hijacks within only ≈5min. In addition, it only reports ≈17.5 suspicious cases every day for the whole Internet, a small number that allows operators to investigate the reported cases and take countermeasures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b4e6a6cc-9732-4c0a-9e40-f443173ae65eCited by top-tier papers1
Ask how each one uses itBuilds on4
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 473 citations
- Understanding Negative Sampling in Graph Representation LearningZhen Yang, Ming Ding, Chang Zhou, Hongxia Yang et al.KDD 2020 · 172 citations
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
Related papers
- Ares: Comprehensive Path Hijacking Detection via Routing TreeYinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang et al.USENIX Security 2025
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya et al.NDSS 2025
- DISCO: Sidestepping RPKI's Deployment BarriersTomas Hlavacek, Ítalo Cunha, Yossi Gilad, Amir Herzberg et al.NDSS 2020
- ImpROV: Measurement and Practical Mitigation of Collateral Damage in RPKI Route Origin ValidationWeitong Li, Yuze Li, Taejoong ChungUSENIX Security 2025
- IRRedicator: Pruning IRR with RPKI-Valid BGP InsightsMinhyeok Kang, Weitong Li, Roland van Rijswijk-Deij, Ted Taekyoung Kwon et al.NDSS 2024
