A taxonomy of attacks using BGP blackholing

Miller, Loïc;Pelsser, Cristel
(2019) 24th European Symposium on Research in Computer Security — Location: Luxembourg (23.September.2019)

Files

Pelsser_ICTM32.pdf
  • Open Access
  • Adobe PDF
  • 377.47 KB

Details

Authors
Abstract
BGP blackholing is a common technique used to mitigate DDoS at-tacks. Generally, the victim sends in a request for traffic to the attacked IP(s) to be dropped. Unfortunately, remote parties may misuse blackholing [57, 29] and send requests for IPs they do not own, turning a defense technique into a new attack vector. As DDoS attacks grow in number, blackholing will only become more popular, creating a greater risk this service will be exploited. In this work, we de-velop a taxonomy of attacks combining hijacks with blackholing: BGP blackjacks (blackhole hijacks). We show that those attacks effectively grant more reach and stealth to the attacker than regular hijacks, and assess the usability of those attacks in various security deployments. We then find that routing security mechanisms for BGP [30, 31] do not provide an adequate protection against some of those at-tacks, and propose additional mechanisms to properly defend against or mitigate them.
Affiliations

Citations

Miller, L., & Pelsser, C. (2019). A taxonomy of attacks using BGP blackholing. In Sako, K., Schneider, S., Ryan, P. (ed.), Computer Security – ESORICS 2019 (p. p. 107-127). Springer. https://doi.org/10.1007/978-3-030-29959-0_6