iSPY: Detecting IP Pre x Hijacking on My Own Zheng Zhang Purdue University Ying Zhang University of Michigan Y. Charlie Hu Purdue University Z. Morley Mao University of Michigan Randy Bush IIJ ABSTRACT IP pre x hijacking remains a major threat to the security of the Internet routing system due to a lack of authoritative pre x ownership information. Despite many efforts in designing IP pre x hijack detection schemes, no existing design can satisfy all the critical requirements of a truly effective system: real-time, accurate, light-weight, easily and incrementally deployable, as well as robust in victim noti cation. In this paper, we present a novel approach that ful lls all these goals by monitoring network reachability from key external transit networks to one s own network through lightweight pre x-owner-based active probing. Using the pre x-owner s view of reachability, our detection system, I SPY, can differentiate between IP pre x hijacking and network failures based on the observation that hijacking is likely to result in topologically more diverse polluted networks and unreachability. Through detailed simulations of Internet routing, 25-day deployment in 88 ASes (108 pre xes), and experiments with hijacking events of our own pre x
/lp/association-for-computing-machinery/ispy-detecting-ip-prefix-hijacking-on-my-own-9j1X2t0dKX