Using Bursty Announcements for Early Detection of BGP Routing Anomalies

05/14/2019
by   Pablo Moriano, et al.
0

Despite the robust structure of the Internet, it is still susceptible to disruptive routing updates that prevent network traffic from reaching its destination. In this work, we propose a method for early detection of large-scale disruptions based on the analysis of bursty BGP announcements. We hypothesize that the occurrence of large-scale disruptions is preceded by bursty announcements. Our method is grounded in analysis of changes in the inter-arrival times of announcements. BGP announcements that are associated with disruptive updates tend to occur in groups of relatively high frequency, followed by periods of infrequent activity. To test our hypothesis, we quantify the burstiness of inter-arrival times around the date and times of three large-scale incidents: the Indosat hijacking event in April 2014, the Telecom Malaysia leak in June 2015, and the Bharti Airtel Ltd. hijack in November 2015. We show that we can detect these events several hours prior to when they were originally detected. We propose an algorithm that leverages the burstiness of disruptive updates to provide early detection of large-scale malicious incidents using local collector data. We describe limitations, open challenges, and how this method can be used for large-scale routing anomaly detection.

READ FULL TEXT
research
10/17/2017

Internet Anomaly Detection based on Complex Network Path

Detecting the anomaly behaviors such as network failure or Internet inte...
research
12/25/2020

Graph Convolutional Networks for traffic anomaly

Event detection has been an important task in transportation, whose task...
research
01/22/2021

A Fast-Convergence Routing of the Hot-Potato

Interactions between the intra- and inter-domain routing protocols recei...
research
02/25/2019

Anomaly Detection for an E-commerce Pricing System

Online retailers execute a very large number of price updates when compa...
research
06/19/2018

CommunityWatch: The Swiss-Army Knife of BGP Anomaly Detection

We present CommunityWatch, an open-source system that enables timely and...
research
06/26/2021

Detecting anomalies in heterogeneous population-scale VAT networks

Anomaly detection in network science is the method to determine aberrant...
research
01/13/2023

A Framework for the Evaluation of Network Reliability Under Periodic Demand

In this paper, we study network reliability in relation to a periodic ti...

Please sign up or login with your details

Forgot password? Click here to reset