Detecting BGP Route Anomalies with Deep Learning

Kyle McGlynn, Hrishikesh B. Acharya, Minseok Kwon · 2019

Fake or mistaken BGP updates can cause serious damage to Internet routing. We note that an expert network administrator can develop a “gut feeling” that lets them identify mistaken or attack updates. Might it be possible to capture such intuition in a learning-based anomaly detection mechanism? Our idea is that good route updates share characteristics which bad updates do not, and even if such characteristics are subtle (i.e. cannot be captured in clear rules), they can be learned. More specifically, an auto-encoder (trained on known-good BGP routing data) will successfully encode good route updates, but will perform more poorly with random or malicious updates. In our system, we use two auto-encoders, each trained to detect a specific type of anomalous BGP update. If either auto-encoder performs poorly (i.e. shows large differences between input and output), we report the BGP update as likely-anomalous. Our detector shows promising early results in identifying anomalous MOAS conflicts as well as prefix hijack attacks.

Read the paper · More papers on PaperTik