Kirin: Hitting the Internet with Distributed BGP Announcements

Title Kirin: Hitting the Internet with Distributed BGP Announcements
Journal ACM Asia Conference on Computer and Communications Security
Year 2024
Status Published
DOI https://doi.org/10.1145/3634737.3657000
URL https://dl.acm.org/doi/abs/10.1145/3634737.3657000
Abstract <p>The Internet is a critical resource in the daily life of billions of<br />
users. To support the growing number of users and their increasing<br />
demands, operators continuously scale their network footprint—<br />
e.g., by joining Internet Exchange Points (IXPs)—and adopt relevant<br />
technologies—such as IPv6—which provides a vastly larger address<br />
space than its predecessor.</p>

<p>In this paper, we revisit prefix de-aggregation attacks in the light<br />
of these two changes and introduce Kirin—an advanced BGP prefix<br />
de-aggregation attack that announces millions of IPv6 routes via<br />
thousands of IXP connections to overflow the memory of routers<br />
within remote ASes. Kirin’s highly distributed nature allows it<br />
to bypass traditional route-flooding defense mechanisms, such as<br />
per-session prefix limits or route flap damping.</p>

<p>We analyze Kirin’s theoretical feasibility by formulating it as a<br />
mathematical optimization problem, test for practical hurdles by<br />
deploying enough infrastructure to perform a micro-scale Kirin<br />
attack using 4 IXPs, and validate our assumptions via BGP data<br />
analysis, real-world measurements, and router testbed experiments.<br />
Despite its low deployment cost, we find that Kirin may inject lethal<br />
amounts of routes into the routers of thousands of ASes.</p>
Publisher ACM
ISBN 979-8-4007-0482-6/24/07
PDF 3634737.3657000.pdf