Classification of legitimate multi-origin AS announcements

Determine how to distinguish legitimate Multi-Origin AS announcements from routing anomalies using reliable ground-truth labels.

Background

RouteLLM focuses on prefix hijacking, path hijacking, and route leaks. A legitimate Multi-Origin AS (MOAS) announcement can resemble a prefix hijacking because multiple ASes may legitimately originate the same prefix.

The paper explicitly excludes distinguishing legitimate MOAS announcements from routing anomalies because public mailing lists do not provide sufficient ground-truth labels. Establishing a reliable classification method and obtaining or constructing suitable labels remain unresolved.

References

Please note that this work does not attempt to distinguish legitimate Multi-Origin AS (MOAS) announcements from routing anomalies, as ground-truth labels for legitimate MOAS cannot be obtained from public mailing lists. We leave the classification of legitimate MOAS to future work.

The Surprising Effectiveness of LLMs in BGP Security: Mining An Unprecedented Amount of Incidents and Boosting Anomaly Detection  (2608.22812 - Liu et al., 24 Aug 2026) in Appendix, Section “Extended Background and Motivation,” subsection “Routing Anomaly Categories”