Modeling the BGP Prefix Hijack via Pollution and Recovery Processes
摘要
BGP hijacking events pose a threat to the resilience and security of the internet system, and proposed mechanisms for defense, detection, and mitigation currently cannot eliminate the impact of such events. In this paper, we selected 1,227 suspected BGP prefix hijacking events targeting China in 2023 for analysis and modeling to assess the pollution impact of these events. Through statistical analysis of the geographical and temporal characteristics of the event data, we found that most of the events were short-lived and had a low level of threat. Similarly, in the AS topology, the event-related nodes were also located at the edges of the network. Notably, after feature analysis, we discovered the existence of concurrent hijacking events. To quantify the impact of BGP prefix hijacking events on individual networks and the overall network, we proposed a routing pollution model based on triggered updates from the perspective of propagation, as well as a routing recovery model after removing the hijacker nodes, based on the results of feature analysis. Our simulation results indicate that most hijacking events have a small contamination scope and are easily recoverable, even if they persist for a long time. By quantitatively analyzing the impact of hijacking events targeting China in 2023, we can better understand the threats in the internet security environment and provide suggestions for defense and recovery strategies.