PathProb: Probabilistic Inference and Path Scoring for Enhanced and Flexible BGP Route Leak Detection
Yingqian Hao, Hui Zou, Lu Zhou, Yuxuan Chen, Yanbiao Li
摘要
The Border Gateway Protocol (BGP) lacks inherent security, leaving the Internet vulnerable to severe threats like route leaks. Existing detection methods suffer from limitations such as rigid binary classification, high false positives, and sparse authoritative AS relationship data. To address these challenges, this paper proposes PathProb-a novel paradigm that flexibly identifies route leaks by calculating topology-aware probability distributions for AS links and computing legitimacy scores for AS paths. Our approach integrates Monte Carlo methods with an Integer Linear Programming formulation of routing policies to derive these solutions efficiently. We comprehensively evaluate PathProb using real-world BGP routing traces and route leak incidents. Results show our inference model outperforms state-of-the-art approaches with a high-confidence validation dataset. PathProb detects real-world route leaks with 98.45% recall while simultaneously reducing false positives by 4.29 ∼ 20.08 percentage points over stateof-the-art alternatives. Additionally, PathProb's path legitimacy scoring enables network administrators to dynamically adjust route leak detection thresholds-tailoring security posture to their specific false alarm tolerance and security needs. Finally, PathProb offers seamless compatibility with emerging route leak mitigation mechanisms, such as Autonomous System Provider Authorization (ASPA), enabling flexible integration to enhance leak detection capabilities. Role T1
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection SystemYihao Chen, Qilei Yin, Qi Li, Zhuotao Liu 等USENIX Security 2024 · 被引用 14 次
- Flexsealing BGP Against Route Leaks: Peerlock Active Measurement and AnalysisTyler McDaniel, Jared M. Smith, Max SchuchardNDSS 2021
- BGP-iSec: Improved Security of Internet Routing Against Post-ROV AttacksCameron Morris, Amir Herzberg, Bing Wang, Samuel SecondoNDSS 2024
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya 等NDSS 2025
相关 Paper
- Accurate and Stable AS Relationship Inference via Trusted Seeds and Semi-Supervised LearningSiyuan Teng, Lancheng Qin, Li Chen, Dan Li 等INFOCOM 2026
- Ares: Comprehensive Path Hijacking Detection via Routing TreeYinxiang Tao, Chengwan Zhang, Changqing An, Shuying Zhuang 等USENIX Security 2025
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti 等NSDI 2024 · 被引用 21 次
- Resolution Without Dissent: In-Path Per-Query Sanitization to Defeat Surreptitious Communication Over DNSDaiping Liu, Ruian Duan, Jun WangS&P 2025
- Which way to go? Inferring Fine-Grained AS Paths with PathRadarZitong Jin, Xingang Shi, Qiang Ma, Letong Sun 等INFOCOM 2025 · 被引用 1 次
