SICO: Surgical Interception Attacks by Manipulating BGP Communities
Henry Birge-Lee, Liang Wang, Jennifer Rexford, Prateek Mittal
Abstract
The Border Gateway Protocol (BGP) is the primary routing protocol for the Internet backbone, yet it lacks adequate security mechanisms. While simple BGP hijack attacks only involve an adversary hijacking Internet traffic destined to a victim, more complex and challenging interception attacks require that adversary intercept a victim's traffic and forward it on to the victim. If an interception attack is launched incorrectly, the adversary's attack will disrupt its route to the victim making it impossible to forward packets. To overcome these challenges, we introduce SICO attacks (Surgical Interception using COmmunities): a novel method of launching interception attacks that leverages BGP communities to scope an adversary's attack and ensure a route to the victim. We then show how SICO attacks can be targeted to specific source IP addresses for reducing attack costs. Furthermore, we ethically perform SICO attacks on the real Internet backbone to evaluate their feasibility and effectiveness. Results suggest that SICO attacks can achieve interception even when previously proposed attacks would not be feasible and outperforms them by attracting traffic from an additional 16% of Internet hosts (worst case) and 58% of Internet hosts (best case). Finally, we analyze the Internet topology to find that at least 83% of multi-homed ASes are capable of launching these attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers11
- Continuous in-network round-trip time monitoringSatadal Sengupta, Hyojoon Kim, Jennifer RexfordSIGCOMM 2022 · 54 citations
- TANGO: Secure Collaborative Route Control across the Public InternetHenry Birge-Lee, Sophia Yoo, Benjamin Herber, Jennifer Rexford et al.NSDI 2024 · 12 citations
- Flexsealing BGP Against Route Leaks: Peerlock Active Measurement and AnalysisTyler McDaniel, Jared M. Smith, Max SchuchardNDSS 2021
- ASRogue: Manipulating ASRank-Inferred AS RelationshipsYi Xu, Yihao Chen, Ke Xu, Qi Li et al.USENIX Security 2026
- The Threat Landscape of IP Leasing in the RPKI EraWeitong Li, Yongzhe Xu, Taejoong ChungS&P 2026
Builds on4
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 473 citations
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- Counter-RAPTOR: Safeguarding Tor Against Active Routing AttacksYixin Sun, Anne Edmundson, Nick Feamster, Mung Chiang et al.S&P 2017 · 60 citations
Related papers
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti et al.NSDI 2024 · 21 citations
- Exploiting vulnerabilities at IXP route servers to perform stealth BGP hijacksGabby Rimlinger, Joaquim Pereira, Matthieu Gouel, Olivier Fourmaux et al.CCS 2026
- BGP-iSec: Improved Security of Internet Routing Against Post-ROV AttacksCameron Morris, Amir Herzberg, Bing Wang, Samuel SecondoNDSS 2024
- Creating a Secure Underlay for the InternetHenry Birge-Lee, Joel Wanner, Grace H. Cimaszewski, Jonghoon Kwon et al.USENIX Security 2022
- Ares: Comprehensive Path Hijacking Detection via Routing TreeYinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang et al.USENIX Security 2025
