@inproceedings{bibcite_16002, title = {Kirin: Hitting the Internet with Distributed BGP Announcements}, abstract = {

The Internet is a critical resource in the daily life of billions of
users. To support the growing number of users and their increasing
demands, operators continuously scale their network footprint{\textemdash}
e.g., by joining Internet Exchange Points (IXPs){\textemdash}and adopt relevant
technologies{\textemdash}such as IPv6{\textemdash}which provides a vastly larger address
space than its predecessor.

In this paper, we revisit prefix de-aggregation attacks in the light
of these two changes and introduce Kirin{\textemdash}an advanced BGP prefix
de-aggregation attack that announces millions of IPv6 routes via
thousands of IXP connections to overflow the memory of routers
within remote ASes. Kirin{\textquoteright}s highly distributed nature allows it
to bypass traditional route-flooding defense mechanisms, such as
per-session prefix limits or route flap damping.

We analyze Kirin{\textquoteright}s theoretical feasibility by formulating it as a
mathematical optimization problem, test for practical hurdles by
deploying enough infrastructure to perform a micro-scale Kirin
attack using 4 IXPs, and validate our assumptions via BGP data
analysis, real-world measurements, and router testbed experiments.
Despite its low deployment cost, we find that Kirin may inject lethal
amounts of routes into the routers of thousands of ASes.

}, year = {2024}, journal = {ACM Asia Conference on Computer and Communications Security}, month = {07/2024}, publisher = {ACM}, address = {Singapore}, isbn = {979-8-4007-0482-6/24/07}, url = {https://dl.acm.org/doi/abs/10.1145/3634737.3657000}, doi = {https://doi.org/10.1145/3634737.3657000}, language = {eng}, }