North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: odd hijack

  • From: Nick Feamster
  • Date: Fri Nov 10 12:03:02 2006

On Fri, Nov 10, 2006 at 11:01:02AM +0000, steve@telecomplete.co.uk wrote:
> 
> the preso link is below, you didnt read it yet.. :)
> 
> you can hijack any address space providing your route is preferred either because it is more specific, less specific, shorter as-path.. 

Slides 13-15 of our Feb 2006 NANOG talk show examples of this and describe the
motivation.  

The technique us also described in detail in our SIGCOMM paper, along with
several other observations about why doing things like looking at "uncommon
origin ASes" to detect a determined hijacker is unlikely to ever be successful
at detecting a malicious hijack (as opposed to a misconfiguration).

-Nick