A Light-Weight Distributed Scheme for Detecting IP Prefix Hijacks in Real-Time

Source: Association for Computing Machinery

Favorite

Free registration required

As more and more Internet IP prefix hijacking incidents are being reported, the value of hijacking detection services has become evident. Most of the current hijacking detection approaches monitor IP prefixes on the control plane and detect inconsistencies in route advertisements and route qualities. The authors propose a different approach that utilizes information collected mostly from the data plane. The method is motivated by two key observations: when a prefix is not hijacked, the hop count of the path from a source to this prefix is generally stable; and the path from a source to this prefix is almost always a super-path of the path from the same source to a reference point along the previous path, as long as the reference point is topologically close to the prefix.
Format:PDF Size:430.72
Date:Aug 2007