Skip to main content
eScholarship
Open Access Publications from the University of California

Visual-based anomaly detection for BGP origin AS change (OASC) events

  • Author(s): Teoh, S T
  • Ma, K L
  • Wu, S F
  • Massey, D
  • Zhao, X L
  • Pei, D
  • Wang, L
  • Zhang, L
  • Bush, R
  • et al.
Abstract

To complement machine intelligence in anomaly event analysis and correlation, in this paper, we investigate the possibility of a human-interactive visual-based anomaly detection system for faults and security attacks related to the BGP (Border Gateway Protocol) routing protocol. In particular, we have built and tested a program, based on fairly simple information visualization techniques, to navigate interactively real-life BGP OASC (Origin AS Change) events. Our initial experience demonstrates that the integration of mechanical analysis and human intelligence can effectively improve the performance of anomaly detection and alert correlation. Furthermore, while a traditional representation of OASC events provides either little or no valuable information, our program can accurately identify, correlate previously unknown BGP/OASC problems, and provide network operators with a valuable high-level abstraction about the dynamics of BGP.

Many UC-authored scholarly publications are freely available on this site because of the UC's open access policies. Let us know how this access is important for you.

Main Content
Current View