Global Internet Routing Forensics: Validation of BGP Paths Using ICMP Traceback.
Eunjong Kim, Daniel F. Massey, Indrajit Ray · 2005
Abstract Nearly all network applications rely on the global Internet routing infrastructure to compute routes and deliver packets. Unfortunately, false Internet routes can be maliciously introduced with relative ease into the routing infrastructure. This is because Border Gateway Protocol (BGP), the Internet’s global routing protocol, lacks basic authentication and monitoring functionalities. If false routes are introduced, it can lead to total collapse of packet forwarding leading to denial of service or misdirected traffic. Currently, it is impossible to prevent such malicious injection of false traffic routes. We believe that an ability to identify false paths through efficient validation, proper recording and forensic analysis of routing data, will considerably help in the prosecution of the miscreant and will act as a strong deterrent. In this work we propose such a mechanism. For each path information, we use ICMP (Internet Control Message Protocol) traceback message with AS-PATH information and link connectivity information. Our path verification technique is proportional to the amount of traffic carried on a path, uses efficient off-line verification technique with which each router independently and dynamically keeps track of local database, and allows a destination to monitor its routes, detect false paths used by remote sites, and record routing data for later forensic analysis in the event of an attack. Last but not the least, our approach does not require modifications to the BGP protocol and hence can be easily deployed.