Authors :
Kudzai Chiomba; Macdonald Mukosera
Volume/Issue :
Volume 11 - 2026, Issue 6 - June
Google Scholar :
https://tinyurl.com/5ke9nttf
Scribd :
https://tinyurl.com/bde5a28f
DOI :
https://doi.org/10.38124/ijisrt/26jun1527
Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.
Abstract :
The Border Gateway Protocol (BGP) forms the foundation of global internet routing, yet it contains no native mechanism to verify that an autonomous system (AS) is authorised to announce a given IP prefix. This fundamental weakness enables two critical attack classes: prefix hijacking, where an unauthorized AS announce ownership of an IP block it does not legitimately control, and route leaking, where routes are propagated with abnormally inflated AS paths. Present monitoring frameworks – including BGPStream, RIPE Stat, and BGPlay – provide data collection and historical visualisation capabilities, though they lack integrated, real-time operator guidance. This paper presents lightweight BGP Route Monitoring and Visualization Tool built on the Detect-Explain-Act (DEA) framework, validated on a six-router EVE-NG topology. The tool polls a monitoring router via Telnet, parses the BGP routing table, applies two rule-based detection algorithms, and enriches each anomaly with a plain-language explanation and prioritized remediation steps displayed on a Flask web dashboard. Experimental testing across six attack cases – including cross-ISP hijacks, provider-level prefix theft, cascade route leaks, and compound attacks – achieved 100% detection rate, 0% false positive rate on a verified clean baseline, and sub-30-second detection latency. The tool outperforms all three comparison frameworks on route leak detection, operator explanation, and effective guidance.
Keywords :
BGP Security; Prefix Hijacking; Route Leaking; Anomaly Detection; Real-Time Monitoring; Detect-Explain-Act; AS Path Analysis; Network Visualization; Internet Routing Security.
References :
- Y. Rekhter, T. Li, and S. Hares, "A Border Gateway Protocol (BGP-4)," RFC 4271, IETF, Jan. 2006.
- S. Kent, C. Lynn, and K. Seo, "Secure Border Gateway Protocol (S-BGP)," IEEE J. Sel. Areas Commun., vol. 18, no. 4, pp. 582–592, Apr. 2000.
- P. Bangera, "Impact of Prefix Hijacking on Payments of Providers," M.S. thesis, Dept. Telecommunications, Aalto University, Espoo, Finland, 2010.
- R. Owen, A. Bryant, L. Finch, D. Franklin, M. Abdollahi, and M. Abolhasan, "Failures and Resilience in the IP Era: Navigating the Fragility of Modern Telecommunications Networks: The Sovereign Functions," IEEE Access, vol. 13, pp. 1–20, 2025.
- A. Aris, S. F. Oktug, S. Bingol, and A. Lakhina, "BGPStream: A Software Framework for Live and Historical BGP Data Analysis," in Proc. ACM Internet Measurement Conf. (IMC), Tokyo, Japan, 2016, pp. 429–444.
- C. C. Gray, P. D. Ritsos, and J. C. Roberts, "Contextual Network Navigation to Provide Situational Awareness for Network Administrators," in Proc. IEEE Symp. Visualization for Cyber Security (VizSec), Chicago, IL, USA, Oct. 2015, pp. 1–8.
- L. Colitti, G. Di Battista, F. Mariani, M. Patrignani, and M. Pizzonia, "Visualizing Interdomain Routing with BGPlay," J. Graph Algorithms Appl., vol. 9, no. 1, pp. 117–148, 2005.
- M. Lad, D. Massey, D. Pei, Y. Wu, B. Zhang, and L. Zhang, "PHAS: A Prefix Hijack Alert System," in Proc. USENIX Security Symp., Vancouver, BC, Canada, 2006, pp. 153–166.
- X. Shi, Y. Xiang, Z. Wang, X. Yin, and J. Wu, "Detecting Prefix Hijackings in the Internet with Argus," in Proc. ACM Internet Measurement Conf. (IMC), Berlin, Germany, 2012, pp. 15–28.
- C. Shen, R. Wang, X. Li, P. Zhang, K. Liu, and L. Tan, "Border Gateway Protocol Route Leak Detection Technique Based on Graph Features and Machine Learning," Electronics, vol. 13, no. 20, p. 4072, Oct. 2024.
- J. Kuforiji, "Digital Forensics and Incident Response (DFIR) Automation: Leveraging AI to Accelerate Breach Investigation, Evidence Collection, and Cyberattack Mitigation," J. Data Analysis Critical Manage., vol. 1, no. 4, pp. 1–19, 2025.
- J. Mauch, J. Snijders, and G. Hankins, "Default EBGP Route Propagation Behaviour Without Policies," RFC 8212, IETF, Jul. 2017.
The Border Gateway Protocol (BGP) forms the foundation of global internet routing, yet it contains no native mechanism to verify that an autonomous system (AS) is authorised to announce a given IP prefix. This fundamental weakness enables two critical attack classes: prefix hijacking, where an unauthorized AS announce ownership of an IP block it does not legitimately control, and route leaking, where routes are propagated with abnormally inflated AS paths. Present monitoring frameworks – including BGPStream, RIPE Stat, and BGPlay – provide data collection and historical visualisation capabilities, though they lack integrated, real-time operator guidance. This paper presents lightweight BGP Route Monitoring and Visualization Tool built on the Detect-Explain-Act (DEA) framework, validated on a six-router EVE-NG topology. The tool polls a monitoring router via Telnet, parses the BGP routing table, applies two rule-based detection algorithms, and enriches each anomaly with a plain-language explanation and prioritized remediation steps displayed on a Flask web dashboard. Experimental testing across six attack cases – including cross-ISP hijacks, provider-level prefix theft, cascade route leaks, and compound attacks – achieved 100% detection rate, 0% false positive rate on a verified clean baseline, and sub-30-second detection latency. The tool outperforms all three comparison frameworks on route leak detection, operator explanation, and effective guidance.
Keywords :
BGP Security; Prefix Hijacking; Route Leaking; Anomaly Detection; Real-Time Monitoring; Detect-Explain-Act; AS Path Analysis; Network Visualization; Internet Routing Security.