The security of Border Gateway Protocol (BGP) operations at Internet Exchange Points (IXPs) is critical to ensuring the integrity of data exchanges between Internet Service Providers (ISPs). A key challenge in BGP is its trust-based route sharing, which introduces vulnerabilities that attackers can exploit to hijack or disrupt traffic. While mechanisms like Internet Routing Registries (IRRs) and the Resource Public Key Infrastructure (RPKI) have been developed to mitigate these risks, their effectiveness is often undermined by inherent design flaws that limit their reliability. This paper presents a novel tool designed to address these security gaps in IXP infrastructures. By analyzing the Routing Information Base (RIB) of an IXP's route server, the tool identifies possible prefix hijacking attacks. These prefixes serve as input for calculating a Risk Level metric for each Autonomous System (AS), offering IXP operators insights into anomalous behaviors. The effectiveness of the metric is validated through its application to well-known attack scenarios. Finally, we showcase the application of this tool through an analysis of real-world data from the route server of a major Italian IXP.
Estimating autonomous system risk levels by analyzing IXP route server RIB / Servillo, Stefano; Spadaccino, Pietro; Luciani, Flavio; Cuomo, Francesca. - In: COMPUTER COMMUNICATIONS. - ISSN 1873-703X. - 237:(2025). [10.1016/j.comcom.2025.108154]
Estimating autonomous system risk levels by analyzing IXP route server RIB
Stefano Servillo;Pietro Spadaccino;Francesca Cuomo
2025
Abstract
The security of Border Gateway Protocol (BGP) operations at Internet Exchange Points (IXPs) is critical to ensuring the integrity of data exchanges between Internet Service Providers (ISPs). A key challenge in BGP is its trust-based route sharing, which introduces vulnerabilities that attackers can exploit to hijack or disrupt traffic. While mechanisms like Internet Routing Registries (IRRs) and the Resource Public Key Infrastructure (RPKI) have been developed to mitigate these risks, their effectiveness is often undermined by inherent design flaws that limit their reliability. This paper presents a novel tool designed to address these security gaps in IXP infrastructures. By analyzing the Routing Information Base (RIB) of an IXP's route server, the tool identifies possible prefix hijacking attacks. These prefixes serve as input for calculating a Risk Level metric for each Autonomous System (AS), offering IXP operators insights into anomalous behaviors. The effectiveness of the metric is validated through its application to well-known attack scenarios. Finally, we showcase the application of this tool through an analysis of real-world data from the route server of a major Italian IXP.| File | Dimensione | Formato | |
|---|---|---|---|
|
Servillo_Estimating_2025.pdf
accesso aperto
Tipologia:
Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza:
Creative commons
Dimensione
2.69 MB
Formato
Adobe PDF
|
2.69 MB | Adobe PDF |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


