HEAP: Reliable Assessment of BGP Hijacking Attacks
Johann Schlamp, Ralph Holz, Quentin Jacquemart, Georg Carle, Ernst W., Biersack

TL;DR
This paper introduces HEAP, a comprehensive tool that improves the detection and validation of BGP hijacking attacks by integrating multiple data sources and analysis techniques to reduce false alarms and accurately assess attack impact.
Contribution
The paper presents HEAP, a novel system that enhances BGP hijacking detection by combining formal modeling, data analysis, and validation methods to improve accuracy and reliability.
Findings
HEAP effectively reduces false positives in hijacking detection.
Routing anomalies are mostly harmless according to analysis.
HEAP can validate and cross-check hijacking alarms.
Abstract
The detection of BGP prefix hijacking attacks has been the focus of research for more than a decade. However, state-of-the-art techniques fall short of detecting more elaborate types of attack. To study such attacks, we devise a novel formalization of Internet routing, and apply this model to routing anomalies in order to establish a comprehensive attacker model. We use this model to precisely classify attacks and to evaluate their impact and detectability. We analyze the eligibility of attack tactics that suit an attacker's goals and demonstrate that related work mostly focuses on less impactful kinds of attacks. We further propose, implement and test the Hijacking Event Analysis Program (HEAP), a new approach to investigate hijacking alarms. Our approachis designed to seamlessly integrate with previous work in order to reduce the high rates of false alarms inherent to these…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting · Network Packet Processing and Optimization
