Skip to content
June 30, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • Technique
  • ARTEMIS: Real-Time Detection and Automatic Mitigation for Border Gateway Protocol (BGP) Prefix Hijacking
  • Technique

ARTEMIS: Real-Time Detection and Automatic Mitigation for Border Gateway Protocol (BGP) Prefix Hijacking

Do Son January 10, 2018 3 minutes read
Border Gateway Protocol

Border Gateway Protocol (BGP) is an autonomous system routing protocol that runs on TCP. It is the basis for the operation of the Internet. However, due to the design time (born in 1989, BGP) is too long, it is inevitable that there is a security risk.

System administrators sometimes incorrectly configure the BGP protocol, causing traffic to be hijacked into advertisements. In some cases, malicious traffic is routed and normal user traffic is hijacked, affecting the user experience.

To this end, a group of researchers from Europe and the United States created a framework called ARTEMIS, which enables service providers to solve BGP hijacking problems in minutes. Researchers say ARTEMIS makes it possible to provide public BGP monitoring services for real-time streaming.

By Johannes Rössel (Self-made, after Image:Bgp-fsm.jpg) [GFDL or CC-BY-SA-3.0], via Wikimedia Commons

Using such infrastructures as RouteViews Project and RIPE Routing Information Services (RIS), ARTEMIS allows operators to ease BGP hijacking in their own infrastructure without having to rely on third-party services. In the view of researchers, this means that network operators using BGP to monitor traffic can respond to BGP hijacking without having to wait for manual verification of the alert.

Network operators can configure ARTEMIS using information from the Autonomous System (AS) to observe external feeds that affect AS-PATH events, which means that the system can detect any type of hijacking event and generate alerts.

The alarms generated by ARTEMIS include various outputs, such as the prefixes affected, the type of hijacking attempts, the observed effects, the AS numbers involved, and the test confidence.

When a BGP hijacking event occurs, ARTEMIS, though it does not let the network operator lose contact with other operators, will split the affected prefixes in response, which is an automatically generated step by the system. When it detects the hijacking of the 10.0.0.0/23 prefix, the network performs prefix splitting and announces two other sub-prefixes: 10.0.0.0/24 and 10.0.1.0/24. These sub-prefixes will be split on the Internet, BGP will prioritize more specific prefixes, and contaminated ASs will re-establish legitimate routes.

BGP MOAS announcements are another part of the ARTEMIS mitigation strategy where mitigation companies use BGP/MOAS or DNS to redirect traffic to their location and cleanup centers, remove malicious traffic, and forward legitimate traffic to victims By.

If BGP hijacking is detected, the ARTEMIS system sends an alert to the enterprise responsible for mitigating the router hijacking the location or prefix, which means that the enterprise is attracting traffic from the Internet and can, therefore, pass the traffic back to the legitimate network.

The researchers said that in the experiment, they could detect BGP hijacking in as little as five seconds and most ASs recovered from hijacking within 60 seconds.

Share this article:

Facebook Post LinkedIn Telegram
Tags: Border Gateway Protocol

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-48558CVSS 10.0
    SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication...
    Admin intelCISA KEV📅 Added to KEV: Jun 29, 2026📅 Updated: Jun 29, 2026
  • CVE-2026-46817CVSS 9.8
    Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected...
    Admin intel📅 Updated: Jun 29, 2026
  • CVE-2026-28496CVSS 9.4
    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template...
    Admin intel📅 Updated: Jun 25, 2026
  • CVE-2026-12569
    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The...
    CISA KEV📅 Added to KEV: Jun 25, 2026
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
    CISA KEV📅 Added to KEV: Jun 23, 2026
  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
    CISA KEV📅 Added to KEV: Jun 23, 2026
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
    CISA KEV📅 Added to KEV: Jun 23, 2026
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
    CISA KEV📅 Added to KEV: Jun 23, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-58138CVSS 9.8
    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability...
  • CVE-2026-48315CVSS 9.3
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input...
  • CVE-2026-48313CVSS 9.3
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation...
  • CVE-2026-48286CVSS 10.0
    Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected...
  • CVE-2026-48283CVSS 10.0
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload...
  • CVE-2026-48282CVSS 10.0
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation...
  • CVE-2026-48281CVSS 10.0
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input...
  • CVE-2026-48277CVSS 10.0
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input...
  • CVE-2026-48276CVSS 10.0
    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload...
  • CVE-2026-58172CVSS 9.1
    Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.