Machine Learning for Detecting the WestRock Ransomware Attack Using BGP Routing Records

Zhida Li,Ana Laura Gonzalez Rios,Ljiljana Trajković
DOI: https://doi.org/10.1109/mcom.001.2200215
IF: 9.03
2023-03-25
IEEE Communications Magazine
Abstract:Border Gateway Protocol (BGP) enables Internet data routing. Hence, its anomalies affect Internet connectivity and cause routing discon-nections, route flaps, and oscillations. Detection of anomalous BGP routing dynamics is a topic of great interest in cybersecurity. In this article, we survey machine learning algorithms for detecting BGP anomalies and intrusions. Gradient boosting decision tree and deep learning algorithms are evaluated by creating models using collected routing records during the WestRock ransomware event. BCPGuard, a BGP anomaly detection tool, has been developed to integrate various stages of the anomaly detection process.
telecommunications,engineering, electrical & electronic
What problem does this paper attempt to address?