ASRogue: Manipulating ASRank-Inferred AS Relationships
Yi Xu, Yihao Chen, Ke Xu, Qi Li, Jianping Wu
摘要
Accurate knowledge of Autonomous System (AS) business relationships is critical for many Internet security and networking tasks. Since these relationships are not publicly visible, operators and researchers rely on algorithms that infer them from empirical routing data. Yet, despite decades of widespread deployment, the security of AS relationship inference against adversarial manipulation remains largely underexplored. To close this gap, we conduct a systematic security analysis of ASRank, a foundational algorithm that underpins many established methods and widely used datasets. We show that ASRank's output is highly sensitive to small, targeted perturbations of AS triplets extracted from BGP paths. Carefully chosen triplet changes can alter inference order and trigger cascading misclassifications. Building on this insight, we present ASROGUE, a manipulation attack against ASRank-based inference. ASROGUE adaptively crafts AS triplets to steer inference order and outcomes, scales triplet injection via prefix splitting and AS-path poisoning, and embeds forged triplets into policy-compliant BGP announcements that can evade common routing defenses. Extensive evaluation shows that when the attacker controls at least two ASes, AS-ROGUE achieves an overall 96.7% manipulation success rate, exceeding 99% for small and medium-sized providers, and remains effective under constrained attack overhead and temporal variation. Finally, controlled experiments on the PEER-ING testbed validate the feasibility of launching ASROGUE attacks in the real-world Internet.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper10
- SICO: Surgical Interception Attacks by Manipulating BGP CommunitiesHenry Birge-Lee, Liang Wang, Jennifer Rexford, Prateek MittalCCS 2019 · 被引用 51 次
- Off-Path TCP Exploits of the Mixed IPID AssignmentXuewei Feng, Chuanpu Fu, Qi Li, Kun Sun 等CCS 2020 · 被引用 39 次
- Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection SystemYihao Chen, Qilei Yin, Qi Li, Zhuotao Liu 等USENIX Security 2024 · 被引用 14 次
- From Address Blocks to Authorized Prefixes: Redesigning RPKI ROV with a Hierarchical Hashing Scheme for Fast and Memory-Efficient ValidationZedong Ni, Yinbo Xu, Hui Zou, Yanbiao Li 等NSDI 2025 · 被引用 3 次
- Suppressing BGP Zombies with Route Status TransparencyYosef Edery Anahory, Jie Kong, Nicholas Scaglione, Justin Furuness 等NSDI 2025 · 被引用 2 次
相关 Paper
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti 等NSDI 2024 · 被引用 21 次
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya 等NDSS 2025
- Withdrawing the BGP Re-Routing Curtain: Understanding the Security Impact of BGP Poisoning through Real-World MeasurementsJared M. Smith, Kyle Birkeland, Tyler McDaniel, Max SchuchardNDSS 2020
- Accurate and Stable AS Relationship Inference via Trusted Seeds and Semi-Supervised LearningSiyuan Teng, Lancheng Qin, Li Chen, Dan Li 等INFOCOM 2026
- Hijacking Bitcoin: Routing Attacks on CryptocurrenciesMaria Apostolaki, Aviv Zohar, Laurent VanbeverS&P 2017 · 被引用 473 次
