BGP eye: a new visualization tool for real-time detection and analysis of BGP anomalies

  • Authors:
  • Soon Tee Teoh;Supranamaya Ranjan;Antonio Nucci;Chen-Nee Chuah

  • Affiliations:
  • San Jose State University, CA;Narus Inc;Narus Inc;University of California, Davis

  • Venue:
  • Proceedings of the 3rd international workshop on Visualization for computer security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Owing to the inter-domain aspects of BGP routing, it is difficult to correlate information across multiple domains in order to analyze the root cause of the routing outages. We present BGP Eye, a tool for visualization-aided root-cause analysis of BGP anomalies. In contrast to previous approaches, BGP Eye performs real-time analysis of BGP anomalies through hierarchical analysis. First, BGP updates are clustered to obtain BGP events that are more representative of an anomaly. These events are then correlated across all border routers to ascertain the extent of the anomaly. Furthermore, BGP Eye provides both the capability to analyze BGP anomalies from an Internet-Centric View through multiple vantage points as well as from a Home-Centric View of a particular Autonomous System. We present the capability for scalable and real-time root-cause analysis provided by BGP Eye through the analysis of two very different anomalies. First, we provide an Internet-Centric view from AS568 of the routing outages during the spread of the Slammer Worm on January 25th, 2003. Second, we provide a Home-Centric view from AS6458 of the routing outages caused by the inadvertent prefix hijacking by AS9121 on December 24th, 2004.