错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Realtime BGP Anomaly Detection Using Graph Centrality Features

  • Janel Huang,
  • Murugaraj Odiathevar,
  • Alvin Valera,
  • Jyoti Sahni,
  • Marcus Frean,
  • Winston K. G. Seah

摘要

Border Gateway Protocol (BGP) anomalies, such as hijacking, is currently growing in trend due to limited detection capabilities. BGP hijacking maliciously reroutes Internet traffic, causing Denial of Service (DoS) to major Internet Service Providers (ISPs) or redirection attacks to Internet users. While it has been shown that BGP anomalies can be detected using machine learning (ML) methods, the features used to train these ML models are not comprehensive. This is because node level features, such as the number of BGP announcements, average Autonomous System (AS) path length and average edit distance do not consider the structure or relationships present in the network graph. In this paper, an approach to extract information from BGP updates to build a network graph is proposed. Then, centrality information is used as features to model the graphical structure of the network to build an early detection tool for BGP anomalies using ML. The proposed method has been validated on real world data from the CenturyLink outage and shows promising results for anomaly detection (as early as one hour before the event was reported) in both individual and a defined group of networks. Furthermore, the anomaly source can be determined using the proposed method.