RA

R.I. Anghel

info

Please Note

3 records found

Still Accurate a Decade Later?

Conference paper (2026) - Radu Anghel, Carlos Gañán, Yury Zhauniarovich
PeeringDB consists of self-reported data and is widely used to facilitate network interconnection, automation, and research, often serving as a ground truth source. However, the accuracy of its data remains a significant concern. In this study, we evaluate the reliability of PeeringDB using a dataset from January 2025. Our analysis finds certain inconsistencies in key data elements. We identified ASNs that remain present in the database despite no longer being assigned. Analysis of self-reported network types reveals that 28.58% of networks either do not report a type or choose not to disclose it, challenging its use to support interconnection decisions. Further comparison of the available network types against their equivalent classifications from ASdb and IPinfo shows considerable disagreement. Manual validation of networks in the "Government"category reveals that only 77.10% of ASNs provided accurate network type. Finally, the consistency check of self-reported prefix counts with routing data from RIPE RIS and CAIDA ASRank indicated significant inconsistencies. Our findings underscore the need for enhanced validation mechanisms to improve the reliability of data provided by PeeringDB for improving its research and operational uses. ...

The Use of UTRS in Combating DDoS Attacks

Conference paper (2024) - Radu Anghel, Swaathi Vetrivel, Elsa Turcios Rodriguez, Kaichi Sameshima, Daisuke Makita, Katsunari Yoshioka, Carlos Gañán, Yury Zhauniarovich
Remotely Triggered Black Hole (RTBH) is a common DDoS mitigation approach that has been in use for the last two decades. Usually, it is implemented close to the attack victim in networks sharing some type of physical connectivity. The Unwanted Traffic Removal Service (UTRS) project offers a free, global, and relatively low-effort-to-join and operate RTBH alternative by removing the requirement of physical connectivity. Given these unique value propositions of UTRS, this paper aims to understand to what extent UTRS is adopted and used to mitigate DDoS attacks. To reach this goal, we collected two DDoS datasets describing amplification and Internet-of-Things-botnet-driven attacks and correlated them with the information from the third dataset containing blackholing requests propagated to the members of UTRS. Our findings suggest that, currently, just a small portion of UTRS members (approximately 10 % ) trigger mitigation attempts: out of 1200+ UTRS members, only 124 triggered blackholing events during our study. Among those, with high probability, 25 Autonomous Systems (ASes) reacted on AmpPot attacks mitigating 0.025 % of them globally or 1.03 % targeting UTRS members; 2 countered IoT-botnet-driven attacks alleviating 0.001 % of them globally or 0.06 % targeting UTRS members. This suggests that UTRS can be a useful tool in mitigating DDoS attacks, but it is not widely used. ...
Journal article (2024) - Radu Anghel, Yury Zhauniarovich, Carlos Gañán
Distributed Denial-of-Service (DDoS) attacks continue to threaten the availability of Internet-based services. While countermeasures exist to decrease the impact of these attacks, not all operators have the resources or knowledge to deploy them. Alternatively, anti-DDoS services such as DDoS clearing houses and blackholing have emerged. Unwanted Traffic Removal Service (UTRS), being one of the oldest community-based anti-DDoS services, has become a global free collaborative service that aims at mitigating major DDoS attacks through the Border Gateway Protocol (BGP). Once the BGP session with UTRS is established, UTRS members can advertise part of the prefixes belonging to their AS to UTRS. UTRS will forward them to all other participants, who, in turn, should start blocking traffic to the advertised IP addresses. In this paper, we develop and evaluate a methodology to automatically detect UTRS participation in the wild. To this end, we deploy a measurement infrastructure and devise a methodology to detect UTRS-based traffic blocking. Using this methodology, we conducted a longitudinal analysis of UTRS participants over ten weeks. Our results show that at any point in time, there were 562 participants, including multihomed, stub, transit, and IXP ASes. Moreover, we surveyed 245 network operators to understand why they would (not) join UTRS. Results show that threat and coping appraisal significantly influence the intention to participate in UTRS. ...