Detecting Selective Dropping Attacks in BGP
Mooi Choo Chuah, Ko Wei Huang · Conference on Local Computer Networks · 2006
Previous studies have shown that current inter-domain routing protocol, border gateway protocol (BGP), is vulnerable to various attacks. Initially, the major concern about BGP security is that malicious BGP routers can arbitrarily falsify BGP routing messages and spread incorrect routing information. Recently, some authors have pointed out the impact of a type of attack, namely selective dropping attack that has not studied before. The authors have shown that such an attack can result in data traffic being blackholed or trapped in a loop. However, the authors did not elaborate on how one can detect selective dropping attacks. In this paper, we present a scheme we designed to detect selective dropping attacks in BGP. We conducted extensive experiments in DETER to evaluate the effectiveness of our scheme using three 30-node AS topologies generated from Brite. Our study shows that our scheme is quite promising