NICRJun 20

HOWLR: A Client-Driven Approach to BGP Hijack Detection

arXiv:2606.218452.0
Predicted impact top 88% in NI · last 90 daysOriginality Incremental advance
AI Analysis

This work empowers end hosts to independently detect BGP hijacking, addressing a critical security gap for network clients.

HOWLR enables end hosts to detect BGP hijacking by using co-hosted TLS-authenticated services as witnesses, protecting 89% of Tor relay prefixes and 75% of Bitcoin pool gateway prefixes.

BGP hijacking enables impersonation attacks in which adversaries divert traffic at the prefix level and serve malicious content to unsuspecting clients. Detecting such attacks has traditionally been the responsibility of network operators, leaving end hosts exposed for hours. We argue that end hosts can detect prefix-level impersonation independently, exploiting a fundamental asymmetry: a BGP hijack diverts traffic for an entire IP prefix, but impersonating every co-hosted service within that prefix is prohibitively difficult at scale, especially if each service is authenticated by a different Certificate Authority. We propose HOWLR, a tool that operationalizes this insight by using co-hosted, TLS-authenticated services as witnesses: if a client can no longer authenticate them, it has evidence of an ongoing attack. This work evaluates the feasibility of this method by quantifying the existence and diversity of witnesses in the wild. We show that HOWLR can protect 89% of Tor relay prefixes, and 75% of Bitcoin pool gateway prefixes.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes