arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.22812cs.NI

大语言模型在BGP安全中的惊人有效性:挖掘前所未有的事件量并提升异常检测

The Surprising Effectiveness of LLMs in BGP Security: Mining An Unprecedented Amount of Incidents and Boosting Anomaly Detection

Libin Liu, Wenzhou Yang, Li Chen, Dan Li, Xiuting Xu

AI总结:

该研究针对BGP安全领域公开路由异常数据集稀缺的问题,开发LLM辅助提取流水线构建了11.89倍于现有规模的基准,设计ROUTELLM检测器并实现远超基线的检测性能,相关资源已开源。

AI中文摘要:

边界网关协议(BGP)安全对互联网基础设施至关重要,但路由异常检测的进展受限于公开可用的事件数据集稀缺,这类数据集仅包含18个已记录案例。我们发现,NANOG和AusNOG等公开运营商邮件列表中包含大量尚未被充分利用的真实世界路由异常报告。为利用这一资源,我们开发了一个大语言模型(LLM)辅助的提取流水线,从历史讨论线程中识别出244个候选事件。经专家验证后,我们整理出一个包含232个已确认路由异常事件的基准数据集,其规模是现有数据集的11.89倍。使用该基准,我们发现现有路由异常检测系统对多样化真实世界事件的泛化能力较差。同时,我们发现一些未经过路由特定适配的通用大语言模型能够识别部分路由异常,但不同模型的性能存在差异,且不足以实现可靠的路由异常检测。受此观察启发,我们设计了ROUTELLM,这是一种基于大语言模型的路由异常检测器,整合了BGP语义感知分词、路由领域适配以及时间感知路由证据检索。实验结果显示,ROUTELLM的事件级准确率达87.13%,消息级准确率达94.65%,分别比最强基线模型高出55.30%和68.50%。我们开源了已验证的路由异常基准、微调后的模型及实现代码,以支持未来BGP安全领域的研究。

英文摘要:

Border Gateway Protocol (BGP) security is critical to Internet infrastructure, yet progress in routing anomaly detection has been limited by the scarcity of publicly available incident datasets, which contain only 18 recorded cases. We observe that public operator mailing lists, e.g., NANOG and AusNOG, contain abundant yet largely untapped reports of real-world routing anomalies. To leverage this source, we develop an LLM-assisted extraction pipeline that identifies 244 candidate incidents from historical discussion threads. After expert validation, we curate a verified benchmark containing 232 confirmed routing anomaly events, making it 11.89X larger than existing dataset. Using this benchmark, we show that existing routing anomaly detection systems generalize poorly to diverse real-world incidents. At the same time, we find that some general-purpose LLMs without routing-specific adaptation can identify a subset of routing anomalies, but their performance varies across models and remains insufficient for reliable routing anomaly detection. Motivated by this observation, we design ROUTELLM, an LLM-based routing anomaly detector that integrates BGP-semantic-aware tokenization, routing-domain adaptation, and time-aware routing evidence retrieval. Experimental results show that ROUTELLM achieves 87.13% event-level accuracy and 94.65% message-level accuracy, outperforming the strongest baselines by 55.30% and 68.50%, respectively. We open-source the verified routing anomaly benchmark, fine-tuned model, and implementation code to support future research on BGP security.

补充信息

↑