Javascript must be enabled to continue!
Detecting and analyzing border gateway protocol blackholing activity
View through CrossRef
SummaryDDoS attack is a traditional malicious attempt to make an authorized system or service inaccessible. Currently, BGP blackholing is an operational countermeasure that builds upon the capabilities of BGP to protect from DDoS attacks. BGP enables blackholing by leveraging the BGP community attribute. This paper presents the analysis of BGP blackholing activity and propose a machine learning‐based mechanism to detect BGP blackholing activity. In BGP blackholing analysis, we find that many networks, including Internet service providers (ISPs) and Internet exchange points (IXPs), offer BGP blackholing service to their customers. We collect networks' blackhole communities and make BGP blackhole communities dictionary. Within 3‐month period (from August to October, 2018), we find a significant number of BGP blackhole announcements (97,532) and distinct blackhole prefixes (8,120). Most of the blackhole prefixes are IPv4 (99.1%). Among IPv4 blackhole prefixes, mostly are /32 (79.9%). The daily patterns of BGP blackholing highlight that there is a variable number of blackhole announcements and distinct blackhole prefixes every day. Furthermore, we apply machine learning techniques to design a BGP blackholing detection mechanism based on support vector machine (SVM), decision tree, and long short‐term memory (LSTM) classifiers. The results are compared based on accuracy and F‐score. Experimental results show that LSTM achieves the best classification accuracy of 95.9% and F‐score of 97.2%. This work provides insights for network operators and researchers interested in BGP blackholing service and DDoS mitigation in the Internet.
Title: Detecting and analyzing border gateway protocol blackholing activity
Description:
SummaryDDoS attack is a traditional malicious attempt to make an authorized system or service inaccessible.
Currently, BGP blackholing is an operational countermeasure that builds upon the capabilities of BGP to protect from DDoS attacks.
BGP enables blackholing by leveraging the BGP community attribute.
This paper presents the analysis of BGP blackholing activity and propose a machine learning‐based mechanism to detect BGP blackholing activity.
In BGP blackholing analysis, we find that many networks, including Internet service providers (ISPs) and Internet exchange points (IXPs), offer BGP blackholing service to their customers.
We collect networks' blackhole communities and make BGP blackhole communities dictionary.
Within 3‐month period (from August to October, 2018), we find a significant number of BGP blackhole announcements (97,532) and distinct blackhole prefixes (8,120).
Most of the blackhole prefixes are IPv4 (99.
1%).
Among IPv4 blackhole prefixes, mostly are /32 (79.
9%).
The daily patterns of BGP blackholing highlight that there is a variable number of blackhole announcements and distinct blackhole prefixes every day.
Furthermore, we apply machine learning techniques to design a BGP blackholing detection mechanism based on support vector machine (SVM), decision tree, and long short‐term memory (LSTM) classifiers.
The results are compared based on accuracy and F‐score.
Experimental results show that LSTM achieves the best classification accuracy of 95.
9% and F‐score of 97.
2%.
This work provides insights for network operators and researchers interested in BGP blackholing service and DDoS mitigation in the Internet.
Related Results
Centaurs transitioning to JFCs: thermal and dynamical evolution
Centaurs transitioning to JFCs: thermal and dynamical evolution
<p>1- Context</p>
<p>Jupiter-family Comets are continuously replenished from their outer solar system reservoirs. Before they enter the in...
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Abstract
The Physical Activity Guidelines for Americans (Guidelines) advises older adults to be as active as possible. Yet, despite the well documented benefits of physical a...
The nexus between territorial border controls, informal cross border trading and economic security in Zimbabwe: the case of Beitbridge Border Post
The nexus between territorial border controls, informal cross border trading and economic security in Zimbabwe: the case of Beitbridge Border Post
Informal cross border trade is central to the lives of many Zimbabweans, with informal trade across the Zimbabwean-South African border being of particular importance. This entails...
Features of legal differentiation of the border sphere in Ukraine
Features of legal differentiation of the border sphere in Ukraine
This scientific article is dedicated to the peculiarities of legal differentiation in the border sphere in Ukraine. The article examines legislative and regulatory acts that have r...
A reliable quality of service aware fault tolerant gateway discovery protocol for vehicular networks
A reliable quality of service aware fault tolerant gateway discovery protocol for vehicular networks
AbstractA great interest in vehicular ad‐hoc networks has been noticed by the research community. General goals of vehicular networks are to enhance safety on the road and to ensur...
8.C. Workshop: Networking for life: How European regions develop/strengthen cross-border health
8.C. Workshop: Networking for life: How European regions develop/strengthen cross-border health
Abstract
The WHO European Programme of Work (2020-2025) emphasizes the importance of “supporting local living environments tha...
Pengelolaan Wilayah Perbatasan Berbasis Integrated Border Management (IBM) dalam Meningkatkan Daya Saing Investasi dan Perdagangan Indonesia
Pengelolaan Wilayah Perbatasan Berbasis Integrated Border Management (IBM) dalam Meningkatkan Daya Saing Investasi dan Perdagangan Indonesia
Position of Indonesia-Singapore borders are ais very strategic, such a position, however, has not been optimally utilized. Borders area is an enticingentrance for investors. Accord...
The cross border trade and its impact on the growth of Lao Bao border town, Quang Tri Province, Vietnam
The cross border trade and its impact on the growth of Lao Bao border town, Quang Tri Province, Vietnam
The thesis aims to study the current trend of cross border trade between Vietnam and Laos though the Lao Bao international checkpoint over the recent years (1998-2010) and the impa...

