Internet Exchange Points (IXPs) play a fundamental role in the exchange of data between Internet Service Providers (ISPs). However, they face one of the main challenges of the Border Gateway Protocol (BGP): trust-based route sharing. This feature introduces a series of vulnerabilities that can be exploited by attackers to hijack or disrupt traffic. Despite the presence of various countermeasures such as Internet Routing Registries (IRRs) or the Resource Public Key Infrastructure (RPKI), the lack of implementation by the majority of Autonomous Systems (ASes), limits their effectiveness. In this paper, we define a tool that supports IXPs operation, enhancing the security of BGP peering in their infrastructure. The proposed approach analyses the information contained in BGP UPDATE messages received by the route-server of an IXP to identify possible prefix hijacking attacks. This set of prefixes are then used to define and compute a \textit{Risk Level} value associated with each AS, providing network operators with an indication of anomalous behaviours. To achieve this objective, data obtained from the route-server one of the main Italian IXP, are examined, showing a real application of our tool.

Autonomous system risk level in the route server infrastructure of an internet exchange point / Servillo, Stefano; Spadaccino, Pietro; Cuomo, Francesca; Luciani, Flavio. - (2024), pp. 387-395. (Intervento presentato al convegno IFIP Networking 2024 tenutosi a Thessaloniki; Greece) [10.23919/IFIPNetworking62109.2024.10619846].

Autonomous system risk level in the route server infrastructure of an internet exchange point

Stefano Servillo;Pietro Spadaccino;Francesca Cuomo;
2024

Abstract

Internet Exchange Points (IXPs) play a fundamental role in the exchange of data between Internet Service Providers (ISPs). However, they face one of the main challenges of the Border Gateway Protocol (BGP): trust-based route sharing. This feature introduces a series of vulnerabilities that can be exploited by attackers to hijack or disrupt traffic. Despite the presence of various countermeasures such as Internet Routing Registries (IRRs) or the Resource Public Key Infrastructure (RPKI), the lack of implementation by the majority of Autonomous Systems (ASes), limits their effectiveness. In this paper, we define a tool that supports IXPs operation, enhancing the security of BGP peering in their infrastructure. The proposed approach analyses the information contained in BGP UPDATE messages received by the route-server of an IXP to identify possible prefix hijacking attacks. This set of prefixes are then used to define and compute a \textit{Risk Level} value associated with each AS, providing network operators with an indication of anomalous behaviours. To achieve this objective, data obtained from the route-server one of the main Italian IXP, are examined, showing a real application of our tool.
2024
IFIP Networking 2024
BGP; routing, security; IXP
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
Autonomous system risk level in the route server infrastructure of an internet exchange point / Servillo, Stefano; Spadaccino, Pietro; Cuomo, Francesca; Luciani, Flavio. - (2024), pp. 387-395. (Intervento presentato al convegno IFIP Networking 2024 tenutosi a Thessaloniki; Greece) [10.23919/IFIPNetworking62109.2024.10619846].
File allegati a questo prodotto
File Dimensione Formato  
Servillo_Autonomous_2024.pdf

solo gestori archivio

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 3 MB
Formato Adobe PDF
3 MB Adobe PDF   Contatta l'autore
Servillo_Indice_Autonomous_2024.pdf

solo gestori archivio

Note: Indice
Tipologia: Altro materiale allegato
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 75.5 kB
Formato Adobe PDF
75.5 kB Adobe PDF   Contatta l'autore
Servillo_Frontespizio_Autonomous_2024.pdf

solo gestori archivio

Note: frontespizio
Tipologia: Altro materiale allegato
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 19.18 kB
Formato Adobe PDF
19.18 kB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1711387
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact