IP Library › Granted Patent US 12,335,336
Granted Patent B2
US 12,335,336 · App. 17/739,875 · Granted Jun 17, 2025

Methods and apparatus for finding global routing hijacks

Inventors: Earl Edward Zmijewski (West Lebanon, NH); Douglas Madory (Lebanon, NH); Alexandr Sergeyev (Bedford, NH)
Assignee: Oracle International Corporation
H04L67/104H04L45/033H04L45/04H04L63/1416H04L63/1466H04L45/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,336
App. No.
17/739,875
Granted
Jun 17, 2025
Kind
B2
Abstract

Every day, thousands of routing “hijacks” occur on the Internet, almost all of them benign. The malicious ones and the resulting misdirection of Internet traffic can be identified by applying sophisticated analytics to extensive global real-time feeds of Border Gateway Protocol (BGP) routing updates. When legitimate attacks are discovered, the automated analysis may be augmented with Domain Name Service (DNS) data (to determine the likely targets), traceroute data (to determine if they represent Man-In-The-Middle exploits), interred business relationships (to understand the scope of the impacts) and even the raw BGP messages. These techniques can be used to uncover attacks against both commercial and government entities.

Claims (87)

1. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

identifying a plurality of prefixes in a border gateway protocol (BGP) update;

determining a particular prefix from among the plurality of prefixes includes one or more private Autonomous System Numbers (ASNs) at a beginning of the particular prefix; and

determining the particular prefix is a potential routing hijack by:

identifying one or more private ASNs at the beginning of the particular prefix;

identifying a next ASN, in the particular prefix, subsequent to the one or more private ASNs;

identifying an origin associated with the next ASN; and

responsive to determining that the origin is a new origin, reporting the particular prefix as a potential routing hijack,

wherein determining that the origin is the new origin comprises determining the origin has not been the origin of any prefix included in any BGP update within a predetermined historical time period.

2. The non-transitory computer readable medium of claim 1 , wherein identifying the next ASN comprises:

traversing the particular prefix from the beginning until an instance of a non-private ASN is identified; and

identifying the instance of the non-private ASN as the next ASN.

3. The non-transitory computer readable medium of claim 1 , wherein reporting the particular prefix as a potential routing hijack is further based on determining the particular prefix is not an RFC1918 prefix.

4. The non-transitory computer readable medium of claim 1 , wherein reporting the particular prefix as a potential routing hijack is further based on:

determining the particular prefix is a Multi-Originated AS (MOAS) prefix; and

the new origin is seen by a number of peers less than a threshold number of peers.

5. The non-transitory computer readable medium of claim 1 , wherein reporting the particular prefix as a potential routing hijack is further based on:

determining the particular prefix does not have a BGP relationship with any origin older than the new origin.

6. The non-transitory computer readable medium of claim 1 , wherein reporting the particular prefix as a potential routing hijack is further based on:

determining the particular prefix was announced by the new origin for an organization; and

the new origin did not previously announce at least one other prefix for the organization.

7. The non-transitory computer readable medium of claim 1 , wherein reporting the particular prefix as a potential routing hijack is further based on:

determining the particular prefix is not associated with a covering prefix originated by the new origin.

8. The non-transitory computer readable medium of claim 1 , wherein identifying the next ASN comprises:

removing from the particular prefix the one or more private ASNs at the beginning of the particular prefix;

subsequent to removing the one or more private ASNs: generating a modified particular prefix such that the next ASN is now at the beginning of the modified particular prefix; and

identifying the next ASN at the beginning of the modified particular prefix.

9. The non-transitory computer readable medium of claim 8 , wherein the operations further comprise:

determining at least one ASN preceding the next ASN in the particular prefix is a single-digit ASN,

wherein generating the modified particular prefix comprises removing the single-digit ASN from the particular prefix.

10. A method, comprising:

identifying a plurality of prefixes in a border gateway protocol (BGP) update;

determining a particular prefix from among the plurality of prefixes includes one or more private Autonomous System Numbers (ASNs) at a beginning of the particular prefix;

determining the particular prefix is a potential routing hijack by:

identifying one or more private ASNs at the beginning of the particular prefix;

identifying a next ASN, in the particular prefix, subsequent to the one or more private ASNs;

identifying an origin associated with the next ASN; and

responsive to determining that the origin is a new origin, reporting the particular prefix as a potential routing hijack,

wherein determining that the origin is the new origin comprises determining the origin has not been the origin of any prefix included in any BGP update within a predetermined historical time period.

11. The method of claim 10 , wherein identifying the next ASN comprises:

traversing the particular prefix from the beginning until an instance of a non-private ASN is identified; and

identifying the instance of the non-private ASN as the next ASN.

12. The method of claim 10 , wherein reporting the particular prefix as a potential routing hijack is further based on determining the particular prefix is not an RFC1918 prefix.

13. The method of claim 10 , wherein reporting the particular prefix as a potential routing hijack is further based on:

determining the particular prefix is a Multi-Originated AS (MOAS) prefix; and

the new origin is seen by a number of peers less than a threshold number of peers.

14. The method of claim 10 , wherein reporting the particular prefix as a potential routing hijack is further based on:

determining the particular prefix does not have a BGP relationship with any origin older than the new origin.

15. The method of claim 10 , wherein reporting the particular prefix as a potential routing hijack is further based on:

determining the particular prefix was announced by the new origin for an organization; and

the new origin did not previously announce at least one other prefix for the organization.

16. The method of claim 10 , wherein identifying the next ASN comprises:

removing from the particular prefix the one or more private ASNs at the beginning of the particular prefix;

subsequent to removing the one or more private ASNs: generating a modified particular prefix such that the next ASN is now at the beginning of the modified particular prefix; and

identifying the next ASN at the beginning of the modified particular prefix.

17. The method of claim 16 , further comprising:

determining at least one ASN preceding the next ASN in the particular prefix is a single-digit ASN,

wherein generating the modified particular prefix comprises removing the single-digit ASN from the particular prefix.

18. A system comprising:

one or more processors; and memory storing instructions that, when executed by the one or more processors, cause the system to perform:

identifying a plurality of prefixes in a border gateway protocol (BGP) update;

determining a particular prefix from among the plurality of prefixes includes one or more private Autonomous System Numbers (ASNs) at a beginning of the particular prefix; and

determining the particular prefix is a potential routing hijack by:

identifying one or more private ASNs at the beginning of the particular prefix;

identifying a next ASN, in the particular prefix, subsequent to the one or more private ASNs;

identifying an origin associated with the next ASN; and

responsive to determining that the origin is a new origin, reporting the particular prefix as a potential routing hijack,

wherein determining that the origin is the new origin comprises determining the origin has not been the origin of any prefix included in any BGP update within a predetermined historical time period.

19. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

identifying a plurality of prefixes in a border gateway protocol (BGP) update;

determining a particular prefix from among the plurality of prefixes includes one or more private Autonomous System Numbers (ASNs) at a beginning of the particular prefix; and

determining the particular prefix is a potential routing hijack by:

identifying one or more private ASNs at the beginning of the particular prefix;

identifying a next ASN, in the particular prefix, subsequent to the one or more private ASNs;

identifying an origin associated with the next ASN at least by:

traversing the particular prefix from the beginning until an instance of a non-private ASN is identified; and

identifying the instance of the non-private ASN as the next ASN; and

responsive to determining that the origin is a new origin, reporting the particular prefix as a potential routing hijack.

20. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

identifying a plurality of prefixes in a border gateway protocol (BGP) update;

determining a particular prefix from among the plurality of prefixes includes one or more private Autonomous System Numbers (ASNs) at a beginning of the particular prefix; and

determining the particular prefix is a potential routing hijack by:

identifying one or more private ASNs at the beginning of the particular prefix;

identifying a next ASN, in the particular prefix, subsequent to the one or more private ASNs;

identifying an origin associated with the next ASN; and

responsive to determining that the origin is a new origin, reporting the particular prefix as a potential routing hijack,

wherein reporting the particular prefix as a potential routing hijack is further based on determining the particular prefix is not an RFC1918 prefix.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2022
From: ZMIJEWSKI, EARL EDWARD; MADORY, DOUGLAS; SERGEYEV, ALEXANDR
To: DYNAMIC NETWORK SERVICES, INC.
Reel/Frame 060587/0542 →
Continuity (3)
Continuation 16078302
Provisional Application 62298169 · Feb 22, 2016
Related Publication 20220263864A1 · Aug 18, 2022
References Cited (21)
US 7823202B1 · Nucci · 2010 [cited by examiner]
US 9729414B1 · Oliveira · 2017 [cited by examiner]
US 10511573B2 · Larson et al. · 2019 [cited by applicant]
US 11418429B2 · Chaturmohta · 2022 [cited by examiner]
US 20050198382A1 · Salmi et al. · 2005 [cited by applicant]
US 20100263041A1 · Shea · 2010 [cited by applicant]
US 20120331555A1 · Retana et al. · 2012 [cited by applicant]
US 20150333983A1 · Ogielski · 2015 [cited by examiner]
US 20170041333A1 · Mahjoub · 2017 [cited by examiner]
US 20190349396A1 · Compton · 2019 [cited by applicant]
US 20210194918A1 · Earl et al. · 2021 [cited by applicant]
CN 101588343A · 2009 [cited by applicant]
CN 102158469A · 2011 [cited by applicant]
CN 102394794A · 2012 [cited by applicant]
CN 105049419A · 2015 [cited by applicant]
JP 2007053430A · 2007 [cited by applicant]
JP 2010200245A · 2010 [cited by applicant]
Deng et al., “Rousseau: A Monitoring System for Interdomain Routing Security”, Communication Networks And Services Research Conference, CNSR 2008, 2008, pp. 255-262. [cited by applicant]
Johann Schlamp, “Investigating the Nature of Routing Anomalies: Closing in on Subprefix Hijacking Attacks,” International Workshop on Traffic Monitoring and Analysis, vol. 9053, Apr. 2015, pp. 173-187. [cited by applicant]
Quentin Jacquemart, “Towards uncovering BGP hijacking attacks,” Networking and Internet Architecture, [cs.NI]. Telecom ParisTech, 2015, pp. 1-190. [cited by applicant]
Schutrup et al., “BGP Hijack Alert System”, Universiteit Van Amsterdam, System and Network Engineering, Research Project 1, Feb. 7, 2016, 41 pages. [cited by applicant]