Pith. sign in

REVIEW 2 cited by

Oscilloscope: Detecting BGP Hijacks in the Data Plane

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2301.12843 v1 pith:5FGCD6LO submitted 2023-01-30 cs.NI

classification cs.NI
keywords traffichijackseventsinternetoscilloscopeprefixesaccuratelyannouncements
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The lack of security of the Internet routing protocol (BGP) has allowed attackers to divert Internet traffic and consequently perpetrate service disruptions, monetary frauds, and even citizen surveillance for decades. State-of-the-art defenses rely on geo-distributed BGP monitors to detect rogue BGP announcements. As we show, though, attackers can easily evade detection by engineering their announcements. This paper presents Oscilloscope, an approach to accurately detect BGP hijacks by relying on real-time traffic analysis. As hijacks inevitably change the characteristics of the diverted traffic, the key idea is to track these changes in real time and flag them. The main challenge is that "normal" Internet events (e.g., network reconfigurations, link failures, load balancing) also change the underlying traffic characteristics - and they are way more frequent than hijacks. Naive traffic analyses would hence lead to too many false positives. We observe that hijacks typically target a subset of the prefixes announced by Internet service providers and only divert a subset of their traffic. In contrast, normal events lead to more uniform changes across prefixes and traffic. Oscilloscope uses this observation to filter out non-hijack events by checking whether they affect multiple related prefixes or not. Our experimental evaluation demonstrates that Oscilloscope quickly and accurately detects hijacks in realistic traffic traces containing hundreds of events.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. BEAR: BGP Event Analysis and Reporting

    cs.NI 2025-06 conditional novelty 7.0 of 10

    A new LLM-based framework automatically produces explanatory reports for BGP hijack and route leak events, claiming 100% accuracy over 54 real and synthetic samples.

  2. Data-Plane Telemetry to Mitigate Long-Distance BGP Hijacks

    cs.NI 2025-07 conditional novelty 6.0 of 10

    HiDe detects long-distance BGP interception attacks by watching per-prefix minimum round-trip times for sudden sustained jumps, using a geolocation-based lower-bound threshold, and it runs at line rate on a Tofino2 pr...

Pith tools