Presentation 2010-07-09
CQ2010-32 A Proposal on BGP Attribute Anomaly Detection
Peng JIANG, Masafumi WATARI, Atsuo TACHIBANA, Shigehiro ANO,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) Following the gradually increased usage of 4-octet ASN (Autonomous System Number), BGP Routing outrages have happened due to improper attribute values (anomalies) of BGP messages. BGP Routing outrages may cause communication reachability unavailable and communication quality deterioration, affecting a large number of Internet users. It is necessary for ISP operators to swiftly determine the cause of an outrage so as to reroute and restore service quality by setting new filtering rules and injecting new operation policies. But pinpointing out quickly the causes of route outrages from enormous number of BGP messages that were collected during the outrage times is very difficult. To solve this problem, authors propose a method of extracting anomaly candidates based on analyzing use frequencies of BGP attribute values. BGP messages are collected passively and use frequencies of BGP attribute values are calculated periodically. Attribute values with low use frequency are extracted as anomaly candidates responsible for BGP routing outrages. This paper explains our proposal in detail and evaluates using real Internet data collected by RouteViews.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) BGP / Anomaly / Detection / Network Management
Paper # CQ2010-32
Date of Issue

Conference Information
Committee CQ
Conference Date 2010/7/1(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Communication Quality (CQ)
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) CQ2010-32 A Proposal on BGP Attribute Anomaly Detection
Sub Title (in English)
Keyword(1) BGP
Keyword(2) Anomaly
Keyword(3) Detection
Keyword(4) Network Management
1st Author's Name Peng JIANG
1st Author's Affiliation ()
2nd Author's Name Masafumi WATARI
2nd Author's Affiliation KDDI R&D Laboratories Inc.
3rd Author's Name Atsuo TACHIBANA
3rd Author's Affiliation KDDI R&D Laboratories Inc.
4th Author's Name Shigehiro ANO
4th Author's Affiliation KDDI R&D Laboratories Inc.
Date 2010-07-09
Paper # CQ2010-32
Volume (vol) vol.110
Number (no) 118
Page pp.pp.-
#Pages 4
Date of Issue