MIT researchers have analyzed a new method that hackers to trick other networks into sending malicious traffic for the purpose of snooping, phishing , or DDoS.
The machine learning is detailed in a paper titled “Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table” and will be presented at a conference in Amsterdam later in October.

ISPs can hijack the Border Gateway Protocol (BGP), falsely advertising the IP address blocks of another network, causing traffic to be redirected. This has cost Amazon, Google, and Microsoft.
To this end, the MIT research team conducted a study titled “serial BGP hijackers.” In it, they examined cases of bad behavior associated with Autonomous System numbers. AS is the way ISPs are identified in BGP route tables.
Although hijacking is usually done by mistake, MIT researchers have explored a machine learning approach to identifying ISPs that frequently hijack over the years. The goal is that a system will allow network engineers to predict false announcements and react more quickly to hijacking events.
The US National Institute of Standards and Technology (NIST) is calling for a public-key cryptographic system that would allow large networks and ISPs to control which networks can advertise a direct connection to address blocks. NIST is also working on BGP validation, so that routers can filter out unauthorized BGP route advertisements.

These measures could mitigate BGP hijacking, however until that happens researchers are working on improving detection and response times.
One of the serial hijackers in the study was AS197426, a Portuguese ISP called BitCanal, due to its multiple hijackings over the years.
There is a theory that the MIT research has the potential to judge ISPs based on their behavior over the years, rather than just looking at isolated incidents.
