{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:05:47Z","timestamp":1784995547576,"version":"3.55.0"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031254598","type":"print"},{"value":"9783031254604","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>One of the most critical building blocks of the reliable operation of the Internet is the Border Gateway Protocol (BGP) that is used to exchange routing messages, signaling active and defective routing paths. During large-scale catastrophic incidents, such as conventional military operations or cyberwarfare, the stability of the Internet is affected, causing the announcements of defective routing paths to increase substantially. This work studies the relation between major incidents, such as armed conflicts in a country scale, and the corresponding network outages observed in the core of the Internet infrastructure as announced by BGP. We focus on the Russo-Ukrainian war as a timely and prominent use case and examine geolocalized BGP data for a 2-month period. Our methodology allows us to cherry-pick long-term network outages among temporary interruptions of service in this specific time window, and pinpoint them to the areas of the operations. Our results indicate that there is a high correlation between the start of military operations and network outages in a city and country level. Furthermore, we show that the last few days before the start of the operations network outages rise as well, indicating that preparatory cyberattack activities take place. No less important, network outages remain at much higher than usual levels during the operations, something that can be attributed to infrastructure destruction possibly backed by cyberattacks.<\/jats:p>","DOI":"10.1007\/978-3-031-25460-4_5","type":"book-chapter","created":{"date-parts":[[2023,2,17]],"date-time":"2023-02-17T09:12:22Z","timestamp":1676625142000},"page":"81-96","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["The Effects of\u00a0the\u00a0Russo-Ukrainian War on\u00a0Network Infrastructures Through the\u00a0Lens of\u00a0BGP"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9481-0906","authenticated-orcid":false,"given":"Zisis","family":"Tsiatsikas","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0142-7503","authenticated-orcid":false,"given":"Georgios","family":"Karopoulos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6455-502X","authenticated-orcid":false,"given":"Georgios","family":"Kambourakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,2,18]]},"reference":[{"key":"5_CR1","doi-asserted-by":"publisher","unstructured":"Palmieri, F., Fiore, U., Castiglione, A., Leu, F.-Y., De Santis, A.: Analyzing the internet stability in presence of disasters. In: Cuzzocrea, A., Kittl, C., Simos, D.E., Weippl, E., Xu, L. (eds.) CD-ARES 2013. LNCS, vol. 8128, pp. 253\u2013268. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-40588-4_18","DOI":"10.1007\/978-3-642-40588-4_18"},{"key":"5_CR2","first-page":"599","volume":"2018","author":"JM Smith","year":"2018","unstructured":"Smith, J.M., Schuchard, M.: Routing around congestion: Defeating DDOS attacks and adverse network conditions via reactive BGP routing. IEEE Symp. Secur. Privacy 2018, 599\u2013617 (2018)","journal-title":"IEEE Symp. Secur. Privacy"},{"key":"5_CR3","doi-asserted-by":"crossref","unstructured":"Rekhter, Y., Li, T., Hares, S.: A Border Gateway Protocol 4 (BGP-4). RFC 4271 (Draft Standard), Internet Engineering Task Force, Jan. 2006, updated by RFCs 6286, 6608, 6793. http:\/\/www.ietf.org\/rfc\/rfc4271.txt","DOI":"10.17487\/rfc4271"},{"key":"5_CR4","unstructured":"Energy Monitor. Russia\u2019s war on Ukraine spotlights critical energy infrastructure. Accessed 24 June 2022. https:\/\/www.energymonitor.ai\/tech\/networks-grids\/russias-war-on-ukraine-spotlights-critical-energy-infrastructure"},{"key":"5_CR5","unstructured":"Endpoint. Russia\u2019s Cyberwar Targets Western Critical Infrastructure. Accessed 24 June 2022. https:\/\/www.tanium.com\/blog\/russias-cyberwar-targets-western-critical-infrastructure\/"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Schulze, M.: Cyber in war: Assessing the strategic, tactical, and operational utility of military cyber operations. In: 2020 12th International Conference on Cyber Conflict (CyCon), vol. 1300, pp. 183\u2013197 (2020)","DOI":"10.23919\/CyCon49761.2020.9131733"},{"issue":"2","key":"5_CR7","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1145\/1232919.1232927","volume":"37","author":"N Kushman","year":"2007","unstructured":"Kushman, N., Kandula, S., Katabi, D.: Can you hear me now?! it must be BGP. SIGCOMM Comput. Commun. Rev. 37(2), 75\u201384 (2007). https:\/\/doi.org\/10.1145\/1232919.1232927","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"5_CR8","unstructured":"Ardelean, D.: BGPDUMP. https:\/\/manpages.debian.org\/"},{"key":"5_CR9","unstructured":"MaxMind Inc. GeoLite country database. http:\/\/dev.maxmind.com\/geoip\/legacy\/geolite"},{"issue":"2","key":"5_CR10","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1145\/1971162.1971171","volume":"41","author":"I Poese","year":"2011","unstructured":"Poese, I., Uhlig, S., Kaafar, M.A., Donnet, B., Gueye, B.: Ip geolocation databases: Unreliable? SIGCOMM Comput. Commun. Rev. 41(2), 53\u201356 (2011). https:\/\/doi.org\/10.1145\/1971162.1971171","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"5_CR11","doi-asserted-by":"publisher","unstructured":"Fedorenko, V., Fedorenko, M.V.: Russia\u2019s military invasion of Ukraine in 2022: Aim, reasons, and implications. Krytyka Prawa. Niezale\u017cne Studia nad Prawem 14(1), 7\u201342 (2022). https:\/\/doi.org\/10.7206\/kp.2080-1084.506","DOI":"10.7206\/kp.2080-1084.506"},{"key":"5_CR12","unstructured":"ComputerWeekly, IT infrastructure used to launch DDoS attack on Russian targets. https:\/\/www.computerweekly.com\/news\/252516773\/IT-infrastructure-used-to-launch-DDoS-attack-on-Russian-targets. Accessed 20 June 2022"},{"key":"5_CR13","unstructured":"Reuters. Russian company websites hit by increased hacking in March, says cyber firm. https:\/\/www.reuters.com\/technology\/russian-company-websites-hit-by-increased-hacking-march-says-cyber-firm-2022-03-11\/"},{"key":"5_CR14","unstructured":"CYBERSCOOP. Putin\u2019s government lists IPs and domains allegedly aiming DDoS traffic at Russia. https:\/\/www.cyberscoop.com\/russian-internet-ddos-incidents-ip-domain-list\/"},{"key":"5_CR15","unstructured":"Emerging cyber threats in the ongoing russia-ukraine conflict. https:\/\/www.cyfirma.com\/outofband\/emerging-cyber-threats-in-the-ongoing-russia-ukraine-conflict\/. Accessed 04 June 2022"},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"Sriram, K., Borchert, O., Kim, O., Gleichmann, P., Montgomery, D.: A comparative analysis of BGP anomaly detection and robustness algorithms. In: Conference for Homeland Security: CATCH \u201909. Cybersecurity Applications Technology, vol. 2009, pp. 25\u201338 (2009)","DOI":"10.1109\/CATCH.2009.20"},{"key":"5_CR17","doi-asserted-by":"crossref","unstructured":"Siganos, G., Faloutsos, M.: Analyzing BGP Policies: Methodology and Tool. In: Proceedings of IEEE INFOCOM, pp. 1640\u20131651 (2004)","DOI":"10.1109\/INFCOM.2004.1354576"},{"key":"5_CR18","unstructured":"Lad, M., Massey, D., Pei, D., Wu, Y., Zhang, B., Zhang, L.: PHAS: A prefix hijack alert system. In: Proceedings of the 15th Conference on USENIX Security Symposium - Volume 15, Ser. USENIX-SS\u201906. USENIX Association, Berkeley (2006). http:\/\/dl.acm.org\/citation.cfm?id=1267336.1267347"},{"key":"5_CR19","doi-asserted-by":"crossref","unstructured":"Karlin, J.: Pretty Good BGP: Improving BGP by cautiously adopting routes. In: Proceedings of International Conference on Network Protocols (2006)","DOI":"10.1109\/ICNP.2006.320179"},{"key":"5_CR20","doi-asserted-by":"crossref","unstructured":"de Urbina Cazenave, I., Kosluk, E., Ganiz, M.: An anomaly detection framework for BGP. In: Innovations in Intelligent Systems and Applications (INISTA), 2011 International Symposium on, pp. 107\u2013111 (2011)","DOI":"10.1109\/INISTA.2011.5946083"},{"key":"5_CR21","doi-asserted-by":"publisher","unstructured":"Li, J., Dou, D., Wu, Z., Kim, S., Agarwal, V.: An internet routing forensics framework for discovering rules of abnormal BGP events. SIGCOMM Comput. Commun. Rev. 35(5), 55\u201366 (2005). https:\/\/doi.org\/10.1145\/1096536.1096542","DOI":"10.1145\/1096536.1096542"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"Li, J., Wu, Z., Purpus, E.: CAM04-5: Toward understanding the behavior of BGP during large-scale power outages. In: Global Telecommunications Conference: GLOBECOM \u201906, vol. 2006, pp. 1\u20135. IEEE (2006)","DOI":"10.1109\/GLOCOM.2006.28"},{"key":"5_CR23","unstructured":"Cowie, J.H., Ogielski, A.T., Premore, B., Smith, E.A., Underwood, T., Corporation, R.: Impact of the 2003 Blackouts on Internet Communications. Tech. Rep. (2003). http:\/\/www.renesys.com\/news"},{"key":"5_CR24","first-page":"2624","volume":"2011","author":"J Li","year":"2011","unstructured":"Li, J., Brooks, S.: I-seismograph: Observing and measuring internet earthquakes in INFOCOM. Proc. IEEE 2011, 2624\u20132632 (2011)","journal-title":"Proc. IEEE"},{"issue":"6","key":"5_CR25","doi-asserted-by":"publisher","first-page":"3411","DOI":"10.1109\/TNET.2017.2748902","volume":"25","author":"M Zhang","year":"2017","unstructured":"Zhang, M., Li, J., Brooks, S.: I-seismograph: Observing, measuring, and analyzing internet earthquakes. IEEE\/ACM Trans. Netw. 25(6), 3411\u20133426 (2017)","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"5_CR26","doi-asserted-by":"publisher","unstructured":"Rexford, J., Wang, J., Xiao, Z., Zhang, Y.: BGP routing stability of popular destinations. In: Proceedings of the 2nd ACM SIGCOMM Workshop on Internet Measurement, ser. IMW \u201902. Association for Computing Machinery, New York (2002), pp. 197\u2013202. https:\/\/doi.org\/10.1145\/637201.637232","DOI":"10.1145\/637201.637232"},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"Hasegawa, G., Kamei, S., Murata, M.: Emergency communication services based on overlay networking technologies. In: Fourth International Conference on Networking and Services (ICNS 2008), pp. 159\u2013164 (2008)","DOI":"10.1109\/ICNS.2008.36"},{"key":"5_CR28","doi-asserted-by":"publisher","unstructured":"Teoh, S.T., Zhang, K., Tseng, S.-M., Ma, K.-L., Wu, S.F.: Combining visual and automated data mining for near-real-time anomaly detection and analysis in BGP. In: Proceedings of the 2004 ACM Workshop on Visualization and Data Mining for Computer Security, ser. VizSEC\/DMSEC \u201904. ACM, New York (2004), pp. 35\u201344. https:\/\/doi.org\/10.1145\/1029208.1029215","DOI":"10.1145\/1029208.1029215"},{"key":"5_CR29","doi-asserted-by":"publisher","unstructured":"Zhang, J., Rexford, J., Feigenbaum, J.: Learning-based anomaly detection in BGP updates. In: Proceedings of the 2005 ACM SIGCOMM Workshop on Mining Network Data, ser. MineNet \u201905, pp. 219\u2013220. ACM, New York (2005). https:\/\/doi.org\/10.1145\/1080173.1080189","DOI":"10.1145\/1080173.1080189"},{"key":"5_CR30","doi-asserted-by":"publisher","unstructured":"Zhang, K., Yen, A., Zhao, X., Massey, D., Wu, S.F., Zhang, L.: On detection of anomalous routing dynamics in BGP. In: Mitrou, N., Kontovasilis, K., Rouskas, G.N., Iliadis, I., Merakos, L. (eds.) NETWORKING 2004. LNCS, vol. 3042, pp. 259\u2013270. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24693-0_22","DOI":"10.1007\/978-3-540-24693-0_22"},{"key":"5_CR31","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Mutz, D., Robertson, W., Valeur, F.: Topology-based detection of anomalous BGP messages. In: Proceedings of the 6th Symposium on Recent Advances in Intrusion Detection (RAID), pp. 17\u201335 (2003)","DOI":"10.1007\/978-3-540-45248-5_2"},{"key":"5_CR32","volume-title":"Global Routing Instabilities During Code Red II and Nimda Worm Propagation","author":"BPJ Cowie","year":"2001","unstructured":"Cowie, B.P.J., Ogielski, A., Yuan, Y.: Global Routing Instabilities During Code Red II and Nimda Worm Propagation. Tech. Rep, Renesys (2001)"},{"key":"5_CR33","doi-asserted-by":"publisher","unstructured":"Lad, M., Zhao, X., Zhang, B., Massey, D., Zhang, L.: Analysis of BGP update surge during slammer worm attack. In: Das, S.R., Das, S.K. (eds.) IWDC 2003. LNCS, vol. 2918, pp. 66\u201379. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-24604-6_7","DOI":"10.1007\/978-3-540-24604-6_7"},{"key":"5_CR34","doi-asserted-by":"publisher","unstructured":"Dainotti, A., Squarcella, C., Aben, E., Claffy, K.C., Chiesa, M., Russo, M., Pescap\u00e9, A.: Analysis of country-wide internet outages caused by censorship. In: Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement Conference, ser. IMC \u201911, pp. 1\u201318. ACM, New York (2011). https:\/\/doi.org\/10.1145\/2068816.2068818","DOI":"10.1145\/2068816.2068818"}],"updated-by":[{"DOI":"10.1007\/978-3-031-25460-4_41","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2024,2,6]],"date-time":"2024-02-06T00:00:00Z","timestamp":1707177600000}}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2022 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-25460-4_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,14]],"date-time":"2024-10-14T13:28:21Z","timestamp":1728912501000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-25460-4_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031254598","9783031254604"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-25460-4_5","relation":{"correction":[{"id-type":"doi","id":"10.1007\/978-3-031-25460-4_41","asserted-by":"object"}]},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"18 February 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"6 February 2024","order":2,"name":"change_date","label":"Change Date","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Correction","order":3,"name":"change_type","label":"Change Type","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"A correction has been published.","order":4,"name":"change_details","label":"Change Details","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2022.compute.dtu.dk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"80","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"48% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1.7","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}