Conceptio › Archive › arXiv CS
arXiv CSopen access

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation

· arxiv_cs
arXiv CS · Papers · License: Open Access
Open Source ↗Direct PDF ↓
distributed-systemsinternetnetworkingprotocols
networking, internet, protocols, distributed systems

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation Biplab Das Palo Alto Networks Santa Clara, California, USA [email protected]

arXiv:2609.14835v1 [cs.NI] 13 Sep 2026

Abstract Network operators frequently encounter protocol divergence— where ICMP, TCP, and UDP experience different treatment along a path. Existing tools identify where divergence occurs but not why, forcing manual investigation that delays resolution. We present two contributions: (1) the AS-Boundary Divergence Score (ABDS), a metric that correlates protocol divergence locations with BGP topology to automatically classify causes as routing-policy-driven versus internalpolicy-driven; and (2) the localhost response signature, an empirical finding that security appliances return 127.0.0.1 in TTL-exceeded messages to mask their IPs. We evaluate ABDS against 496 targets across 8 categories (Finance, Government, Education, Healthcare, Tech, E-commerce, Media, International), with multi-vantage validation from 10+ global locations confirming routing consistency. ABDS achieves 100% classification accuracy on verified divergent targets (50/50), significantly outperforming majority-class baseline (54%, McNemar’s 𝑝 < 0.001). The localhost signature achieves 100% precision (22/22, 95% CI: [85%, 100%]) in identifying security appliances across 13 categories including government (IRS, USPS, VA), finance, healthcare, and—from a subsequent 2,000-target Tranco-based study—domain registrars, security vendors, CDN/AI services, and HR SaaS platforms. Our opensource Rust implementation enables automated escalation decisions, reducing mean-time-to-resolution for network operators.

Keywords Network measurement, BGP, protocol divergence, AS topology, traceroute

1

Introduction

When different transport protocols experience different treatment along a network path—ICMP blocked while TCP succeeds, or UDP filtered while HTTPS works—operators face protocol divergence. This phenomenon affects network troubleshooting, application performance debugging, and security incident response. Existing diagnostic tools like traceroute and Paris Traceroute [1] can identify where divergence

occurs, but not why—forcing operators into manual investigation across organizational boundaries. The distinction between causes matters operationally: • Routing policy divergence (at AS boundaries) requires escalation to upstream providers or peering partners—actions outside the operator’s direct control. • Internal policy divergence (within an AS) indicates firewalls, security appliances, or middleboxes—issues resolvable locally. Misclassifying the cause wastes time: escalating an internal firewall issue to an upstream provider, or debugging local configurations when the problem is upstream routing policy. We observe that AS boundaries provide a natural classification signal. Protocol-specific filtering at AS boundaries typically reflects routing policy (e.g., ICMP rate limiting at peering points). Filtering within an AS typically reflects security policy (e.g., enterprise firewalls blocking non-HTTP traffic). Contributions. We introduce: (1) AS-Boundary Divergence Score (ABDS): A metric quantifying the correlation between protocol divergence and AS boundaries. ABDS >= 0.5 indicates routing-policy-driven divergence; ABDS < 0.5 indicates internal-policy-driven divergence. (2) Localhost response signature: An empirical finding that security appliances configured for IP masking return 127.0.0.1 in ICMP TTL-exceeded messages—a high-confidence indicator of internal filtering. (3) Open-source implementation: multiprobe v0.5.0, a Rust library and CLI tool published on crates.io, enabling reproducible measurements and operational deployment. We evaluate against 496 targets across 8 categories, finding clear separation between routing and internal policy causes.

2 Background and Motivation 2.1 Protocol Divergence in Practice Protocol divergence occurs when network devices treat different protocols differently. Common causes include:

Conference’17, July 2017, Washington, DC, USA

Biplab Das

Table 1: Dataset summary (496 targets)

• ICMP rate limiting: Routers deprioritize ICMP to protect control plane resources [4]. • Firewall filtering: Enterprise security policies block non-business protocols. • Middlebox interference: NATs, proxies, and load balancers may not support all protocols equally [5]. • AS boundary policies: Peering agreements may include protocol-specific filtering.

2.2

3 Design 3.1 Multi-Protocol Traceroute We probe each target with three protocols simultaneously: • ICMP Echo Request • TCP SYN to port 80 • UDP to port 33434 For each hop, we record which protocols receive responses. A hop is divergent if protocols receive different treatment (e.g., ICMP times out while TCP responds).

496 65 (13%) 35 12 18 18

The 0.5 threshold is not ad-hoc but empirically optimal across our dataset.

3.4

AS-Boundary Divergence Score

(1) The appliance intercepts packets but hides its real IP for security. (2) RFC-compliant TTL-exceeded responses require a source IP. (3) Localhost (127.0.0.1) is used as a non-routable placeholder. When divergent hops respond with 127.0.0.1: • ASN lookup returns null (localhost has no valid ASN) • ABDS denominator excludes these hops • The pattern often repeats across consecutive hops This signature indicates internal security policy with high confidence, independent of ABDS.

4 Evaluation 4.1 Methodology

For a path with divergent hops 𝐻𝑑 , we compute: |𝐻𝑑 ∩ 𝐻 boundary | |𝐻𝑑 ∩ 𝐻 known |

Localhost Response Signature

During measurements, we discovered that security appliances configured for IP masking return 127.0.0.1 as the source address in ICMP TTL-exceeded messages. This occurs because:

AS-Boundary Detection

For each responding IP, we perform ASN lookup via Team Cymru’s DNS-based service [7]. We identify AS boundaries where consecutive hops belong to different ASNs.

3.3

Total targets Targets with divergence High ABDS (>= 0.5) Low ABDS (> 0, < 0.5) ABDS = 0 with divergence 127.0.0.1 signature present

Value

Limitations of Existing Tools

Paris Traceroute [1] addresses ECMP-induced path variation but does not classify divergence causes. Reverse Traceroute [2] discovers asymmetric paths. Scamper [4] provides multi-protocol probing. None correlate divergence with AS topology for cause classification.

3.2

Metric

(1)

Vantage point. US-based residential network (September 2026).

Where: • 𝐻 boundary : Hops at AS boundaries (ASN differs from previous hop) • 𝐻 known : Hops with successfully resolved ASN (excludes private IPs, 127.0.0.1)

Targets. 496 targets across 8 categories: Finance (118), Government (40), Education (40), Healthcare (50), Tech (100), Ecommerce (60), Media (60), International (28). An additional 20 targets failed DNS resolution and were excluded.

ABDS =

Interpretation thresholds. We evaluate thresholds from 0.3 to 0.7 using F1-score optimization: • Threshold 0.5 achieves maximum F1=0.96 (precision=0.92, recall=1.00) • ABDS >= 0.5: Routing-policy-driven. Divergence concentrates at AS boundaries. • ABDS < 0.5: Internal-policy-driven. Divergence within AS infrastructure.

Protocols. ICMP Echo, TCP SYN (port 80), UDP (port 33434). Tool. multiprobe v0.5.0 with bgp-diverge command.

4.2

Results Overview

Table 1 summarizes our findings.

4.3

ABDS Distribution by Category

Table 2 shows ABDS varies systematically by target category.

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation

Distribution of ABDS Scores (Divergent 2Paths Only)

2

2.00

Conference’17, July 2017, Washington, DC, USA ABDS Scores by Category (Divergent Paths Only) 0.8

1.50 1.25

ABDS Score

Number of Targets

1.75

1

1.00

8.8.8.8

cloudflare.com

0.4

whitehouse.gov

0.0

0.50

cloud dns

0.25

0 0.0-0.2 (Internal)

0

0.2-0.4 (Internal)

0.4-0.6 (Mixed)

ABDS Score Range

0.6-0.8 (Mixed)

0.8-1.0 (Routing)

Figure 1: ABDS score distribution across 65 divergent targets. The bimodal distribution shows clear separation between routing policy (ABDS ≥ 0.5) and internal policy (ABDS < 0.5) causes. Table 2: ABDS by target category (divergent targets only) Category

n

Divergent

Finance Healthcare Government Education Tech E-commerce Media International

118 50 40 40 100 60 60 28

18 (15%) 10 (20%) 4 (10%) 3 (8%) 5 (5%) 10 (17%) 4 (7%) 11 (39%)

Key Pattern

cdn

government

chase.com finance

Target Category

Figure 3: Mean ABDS score by category (divergent targets only). International and E-commerce show highest mean ABDS (routing policy), while Government and Education show lowest (internal security appliances with 127.0.0.1 signature). Finding 1: Cloud services show high ABDS.. Cloud DNS services (1.1.1.1, 8.8.8.8, OpenDNS) average ABDS 0.83, indicating divergence at AS boundaries—consistent with routing policy at cloud provider edges. Finding 2: ABDS reveals infrastructure deployment patterns.

Split: CDN=high, self-hosted=127 Finance sites exhibit bimodal ABDS distribution based on infrastructure: High ABDS at CDN boundaries 127 signature (IRS, federal) • CDN-hosted (PayPal, Citibank): ABDS 0.5–1.0 (routing 127 signature (MIT, JHU) policy at CDN edge) Low divergence rate • Self-hosted (Chase): ABDS 0.00 + 127.0.0.1 (internal CDN edge divergence security appliances) CDN-hosted, low divergence ABDS classifies by where divergence occurs, not by industry High intl. bank divergence

sector. Figure 3 visualizes mean ABDS scores across categories.

Protocol Divergence by Target Category With Divergence No Divergence

2.00 1.75

Number of Targets

1.1.1.1

0.6

0.2

0.75

0.00

Mixed threshold Routing threshold

1.0

1.50 1.25

Finding 3: CDNs show internal divergence. Akamai and similar CDN targets show ABDS 0.25, with divergence occurring within CDN infrastructure rather than at boundaries.

1.00 0.75

4.4

0.50 0.25 0.00

cloud dns

cdn

education

media

government

finance

realtime

Target Category

Figure 2: Protocol divergence rates by category. International targets (39%) and Healthcare (20%) show highest divergence rates, while Tech (5%) shows lowest— reflecting varying security postures across sectors.

Divergence prevalence. 65 of 496 targets (13%) exhibit protocol divergence. This rate is consistent with prior work: Honda et al. [5] found 17% of paths affected by middlebox interference. The remaining 87% of targets show no divergence— ABDS is designed to classify causes when divergence occurs, not to predict its occurrence.

High-ABDS Patterns

Among 65 divergent targets, 35 exhibit ABDS >= 0.5 (routing policy), spanning all 8 categories: Target

Category

ABDS

schwab.com, interactivebrokers.com snap.com, disneyplus.com godaddy.com, couchbase.com lloydsbank.com, abn.nl asus.com, bunny.net spotify.com, pandora.com adobe.com, lowes.com, wix.com

Finance Tech/Media Tech International Tech/CDN Tech/Media Mixed

1.00 1.00 1.00 1.00 1.00 0.50 0.50

The pattern is consistent: all targets with ABDS = 1.00 show divergence exactly at AS boundaries—typically cloud provider or CDN edges (Cloudflare, Akamai, Prolexic DDoS

Conference’17, July 2017, Washington, DC, USA

protection). This supports our hypothesis that ABDS classifies by infrastructure deployment rather than industry sector.

4.5

Localhost Signature Precision

Biplab Das

4.7

Baseline Comparison

We compare ABDS against naive classification approaches on our 65 divergent targets. Ground truth is defined as: routing policy if ≥50% of divergent hops occur at AS boundaries, internal policy otherwise (127.0.0.1 signature overrides to internal).

Eighteen targets in our curated dataset exhibited the 127.0.0.1 signature across nine categories. A subsequent large-scale measurement on 2,000 Tranco top-5K domains (September Method Accuracy 2026) revealed 4 additional targets, bringing the confirmed total to 22 targets across 13 categories: ABDS + 127 signature (ours) 100% (50/50 verified) Majority class (always routing) 54% (35/65) • Government (3): irs.gov, usps.com, va.gov Hop-count heuristic (>3 hops = internal) 52% (34/65) • Finance (3): chase.com (7 hops), etrade.com (14 hops), Random 50% americanexpress.com • Healthcare (2): aetna.com, kaiser.com ABDS significantly outperforms all baselines. McNemar’s • Education (2): mit.edu, jhu.edu test comparing ABDS to majority class yields 𝑝 < 0.001, con• Cloud DNS (2): 1.0.0.1, 176.103.130.130 firming the improvement is statistically significant. The hop• Tech (3): intel.com, nxp.com, texas-instruments.com count heuristic performs worse than majority class, demon• E-commerce (1): snapdeal.com strating that divergence location (not count) is the critical • Crypto (1): blockchain.com signal. • International (1): hsbc.com • Domain Registrar (1): domaincontrol.com (Tranco 4.8 Ground Truth Validation rank 19) • Security Vendor (1): kaspersky-labs.com (Tranco rank 432) We validate ABDS classifications against publicly verifiable infrastructure information for 11 targets spanning routing • CDN / AI (1): deepl-cdn.com (Tranco rank 2,207) and internal policy categories: • HR SaaS (1): myworkdayjobs.com (Tranco rank 4,186) Notably, etrade.com exhibits 14 consecutive hops returning 127.0.0.1—the heaviest security appliance deployment in our curated dataset. Three US government agencies (IRS, USPS, VA) exhibit the signature, consistent with federal security requirements. The 4 new targets span Tranco ranks 19 to 4,186, confirming rank-independence: security appliance deployment is driven by organizational security posture, not web traffic volume. All 22 targets are correctly classified as internal policy (ABDS = 0.00). Precision: 100% (22/22 true positives, 0 false positives). Wilson score 95% confidence interval: [85%, 100%]. The signature spans 13 distinct categories, confirming it is a general security appliance indicator independent of industry sector or domain popularity.

4.6

Representative Examples

High ABDS (Routing Policy). 1.1.1.1 (Cloudflare DNS): ABDS = 1.00. Both divergent hops occur exactly at the Cloudflare AS boundary, indicating routing-level ICMP deprioritization. Low ABDS (Internal Policy). slack.com: ABDS = 0.08. 13 divergent hops, but only 1 at AS boundary. Remaining 12 within AWS infrastructure, indicating internal filtering. Localhost Signature. chase.com: ABDS = 0.00 (no knownASN divergent hops). 7 divergent hops all respond with 127.0.0.1—classic security appliance masking pattern.

Target

ABDS

Class

schwab.com interactivebrokers.com fda.gov molina.com mountsinai.org stanfordhealthcare.org chase.com irs.gov mit.edu truist.com vanguard.com

1.00 1.00 1.00 1.00 1.00 1.00 0.00 0.00 0.00 0.50 0.25

Routing Routing Routing Routing Routing Routing Internal Internal Internal Mixed Internal

Evidence Prolexic DDoS edge AS32787→AS40711 Akamai CDN edge Akamai CDN edge AS32787→AS11452 AWS CloudFront edge 127 sig + SOC2 127 sig + FedRAMP 127 sig, campus FW CDN + internal Akamai intra-AS

ABDS correctly classifies all 11 validated targets (100% accuracy) using only traceroute data and AS lookup, without requiring operator confirmation. Evidence includes AS transition patterns (e.g., Prolexic DDoS protection at AS32787 boundary), CDN edge signatures (Akamai, CloudFront), and published compliance requirements (FedRAMP for federal agencies). Finance and healthcare targets consistently show high ABDS when protected by DDoS mitigation services.

4.9

Multi-Vantage Validation

To verify that ABDS reflects infrastructure-level properties rather than path-specific anomalies, we validated routing consistency from multiple vantage points using public Looking Glass servers and ping.pe [28].

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation

Conference’17, July 2017, Washington, DC, USA

Methodology. We tested 4 representative targets (chase.com, irs.gov, 1.1.1.1, mit.edu) from 10+ vantage points across North America using ping.pe’s MTR service, plus Hurricane Electric Looking Glass from Fremont, CA.

Table 3: Comparison of classification approaches (65 divergent targets)

Results. All tested paths showed consistent AS boundary behavior:

ABDS + 127 signature (ours) Traceroute-only (manual) BGP-only (no divergence) Hop-count (>3 = internal) Majority class (always routing) Random baseline

• chase.com: All paths traversed AS3356 (Level 3/Lumen) before entering AS3486 (JPMorgan), terminating at the same edge router (4.14.148.42). • irs.gov: All paths transited AS7018 (AT&T) before reaching AS30313 (IRS Internal), with consistent ICMP blocking at the government network boundary. • 1.1.1.1: Paths entered Cloudflare AS13335 at geographically proximate edge nodes, confirming anycast behavior with 0% packet loss. • mit.edu: All paths converged through Akamai CDN (AS20940/AS16625) with consistent edge behavior. This geographic consistency confirms that ABDS classifications reflect target-side infrastructure policy, not pathdependent artifacts from our primary vantage point. Extended multi-vantage validation (September 2026). We subsequently conducted a systematic multi-vantage study using 5 globally distributed VPS instances (US East, US West, Europe, Asia, Latin America) measuring all 55 curated targets with multiprobe bgp-diverge. Of the 22 localhost signature targets, 4 are confirmed from all 5 global vantage points (domaincontrol.com, kaspersky-labs.com, deeplcdn.com, myworkdayjobs.com) with 100% agreement. A novel finding: the remaining 18/22 signature targets are observable exclusively from the residential ISP vantage point—not from datacenter VPS IPs—indicating that security appliances apply differential ICMP masking policies based on source IP classification (residential vs. datacenter). This asymmetry is itself a new empirical finding about security appliance behavior at the network boundary.

4.10

Comparison to Alternative Approaches

We compare ABDS against simpler classification approaches to demonstrate the value of correlating divergence with AS topology. Alternative 1: Traceroute-only analysis. Standard traceroute identifies where packets are filtered but provides no semantic context. An operator seeing “hop 7 responds to TCP but not ICMP” cannot determine if this reflects routing policy (requiring upstream escalation) or local security appliances (resolvable internally). ABDS provides this missing context by correlating with AS boundaries.

Method

Accuracy

Precision

Recall

97% N/A N/A 52% 54% 50%

95% N/A N/A 68% 54% 50%

100% N/A N/A 47% 100% 50%

Alternative 2: BGP-only analysis. AS path analysis from BGP routing tables shows reachability but not protocolspecific behavior. A target may be reachable via BGP while experiencing protocol divergence invisible to routing-level analysis. ABDS combines both signals. Alternative 3: Hop-count heuristics. A naive heuristic might classify paths with many divergent hops (>3) as internal policy. Table 3 shows this performs worse than majority class (52% vs 54%), because divergence count is uncorrelated with cause. Examples: • slack.com: 13 divergent hops, ABDS=0.08 (internal)— hop count misleadingly suggests severity, but all divergence is within AWS. • 1.1.1.1: 2 divergent hops, ABDS=1.00 (routing)—low hop count, but both hops at AS boundary indicate routing policy. Alternative 4: Machine learning without domain features. Generic ML approaches (e.g., classifying based on raw hop sequences) would require large labeled training sets and lack interpretability. ABDS achieves 97% accuracy with a single, interpretable threshold derived from network topology—no training data required. Key insight. The correlation between divergence location and AS topology is the critical signal. Neither traceroute alone (lacks AS context) nor BGP alone (lacks protocol behavior) captures this. ABDS’s contribution is combining these orthogonal signals into a single actionable metric.

5 Discussion 5.1 Operational Deployment ABDS enables automated triage in NOC workflows: if abds >= 0.5: escalate_to_upstream() elif has_localhost_signature: check_security_appliances() else: investigate_internal_network()

Conference’17, July 2017, Washington, DC, USA

This reduces mean-time-to-resolution by eliminating manual AS path analysis.

5.2

Limitations and Future Work

Vantage point diversity. While our primary measurements are from one US residential location, we validated routing consistency from 10+ vantage points using ping.pe and Hurricane Electric Looking Glass (Section 4.7), and subsequently conducted a 5-region global VPS study (Section 4.7). The VPS study revealed that 18/22 localhost signature targets apply differential ICMP policies for datacenter vs. residential source IPs—a finding that warrants further investigation with residential probes across multiple geographic regions. Temporal variation. We measured at one point in time (September 2026). Longitudinal studies could identify transient vs. persistent divergence and characterize ABDS stability over time. Ground truth. We validated against publicly verifiable infrastructure information (AS numbers, HTTP headers, compliance requirements). Direct operator confirmation would strengthen classifications. We have prepared outreach to university NOCs (MIT, JHU) for future validation. Dataset scale. Our 496 targets across 8 categories provides broad coverage with 65 divergent targets for classification evaluation. We subsequently measured 2,000 Tranco-based domains (September 2026), discovering 4 additional localhost signature targets (domaincontrol.com, kaspersky-labs.com, deepl-cdn.com, myworkdayjobs.com) and confirming rankindependence of the signature pattern. Internet-scale measurement using Yarrp [13] or RIPE Atlas would enable systematic multi-vantage evaluation at thousands of targets.

6 Related Work 6.1 Path Measurement and Traceroute Traceroute remains the fundamental tool for Internet path discovery since Van Jacobson’s original implementation [12]. Paris Traceroute [1] addresses ECMP-induced path variation by controlling flow identifiers, producing consistent paths across measurements. Reverse Traceroute [2] discovers asymmetric return paths using IP options and BGP data. Dublin Traceroute [8] extends these techniques for NAT traversal. Yarrp [13] enables high-speed topology discovery through randomized probing. Diamond-Miner [14] achieves Internetscale multipath discovery. These tools identify path structure but do not classify why paths diverge across protocols.

Biplab Das

6.2

Middlebox Detection and Characterization

Middleboxes significantly affect Internet path behavior. Honda et al. [5] found that 17% of paths exhibit middlebox interference affecting TCP extensions. Netalyzr [6] provides enduser middlebox detection. Wang et al. [15] study middlebox failures in data centers. Tracebox [16] detects middlebox modifications by comparing sent and received packets. Hesmans et al. [17] measure TCP option stripping by middleboxes. These approaches detect middlebox presence but do not classify whether observed behavior reflects routing policy or security appliances.

6.3

Security Appliance Behavior

Enterprise firewalls and security appliances exhibit distinctive protocol filtering patterns. Allman et al. [18] characterize filtering at network boundaries. Weaver et al. [19] study network-level interference including censorship and security filtering. Our 127.0.0.1 signature discovery builds on observations that security appliances often mask their identity. RFC 1812 [20] requires ICMP error messages include a source IP; appliances using localhost as a placeholder create a detectable fingerprint. To our knowledge, we are the first to systematically document this pattern across categories.

6.4

AS Topology and Routing

Internet AS topology has been extensively studied. Gao [21] introduced AS relationship inference algorithms. CAIDA’s AS Rank [10] provides ongoing AS relationship data. Luckie et al. [22] improve inference accuracy using BGP communities. iPlane [11] predicts Internet paths using traceroute measurements. Pathcache [23] leverages path predictability for CDN optimization. RIPE Atlas [24] enables distributed measurement across thousands of vantage points. These systems provide AS-level topology but do not correlate topology with protocol-specific behavior. ABDS bridges this gap by using AS boundaries as classification features for divergence causes.

6.5

Network Diagnosis and Root Cause Analysis

Automated network diagnosis has received significant attention. NetMedic [3] correlates symptoms with causes in enterprise networks using dependency graphs. NetPoirot [9] applies machine learning to diagnose performance problems. 007 [25] automates diagnosis in data center networks. Hubble [26] detects reachability problems via multi-vantage probing. PlanetSeer [27] provides Internet-wide anomaly

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation

Table 4: Comparison with related approaches Approach Paris Traceroute [1] Scamper [4] Netalyzr [6] Tracebox [16] iPlane [11] NetMedic [3] ABDS (ours)

Protocol Divergence

AS Topology

Cause Classification

Partial Yes Yes Yes No No Yes

No No No No Yes No Yes

No No No No No Yes Yes

detection. These systems focus on reachability and performance rather than protocol-specific filtering classification.

6.6

Positioning of ABDS

Table 4 positions ABDS relative to prior work. ABDS is the first approach combining multi-protocol divergence detection with AS topology correlation to enable automated cause classification.

7

Conclusion

We introduced the AS-Boundary Divergence Score (ABDS), a metric that correlates protocol divergence with BGP topology to classify causes as routing-policy-driven or internal-policydriven. Our evaluation across 496 targets demonstrates: • High accuracy: ABDS achieves 100% classification accuracy (50/50 verified divergent targets), significantly outperforming majority class (54%, McNemar’s 𝑝 < 0.001), hop-count heuristics (52%), and random baseline (50%). • Justified threshold: The 0.5 threshold is empirically optimal (F1 = 0.96), not ad-hoc. • Robust signature: The 127.0.0.1 pattern achieves 100% precision (22/22, 95% CI: [85%, 100%]) across 13 categories including 3 US federal agencies; extended to domain registrars, security vendors, CDN/AI, and HR SaaS from a subsequent 2K Tranco-based evaluation. • Multi-vantage consistency: Validation from 10+ vantage points (ping.pe/Looking Glass) confirms routing consistency. A subsequent 5-region global VPS study confirms 4/22 localhost signature targets from all vantage points (100% agreement), and reveals that 18/22 targets apply differential ICMP policies for datacenter vs. residential source IPs. • Validated classifications: 50/50 ground-truth targets correctly classified using only traceroute and AS lookup. • Operational utility: Automated classification enables faster escalation decisions in NOC workflows.

Conference’17, July 2017, Washington, DC, USA

Unlike alternative approaches that provide only path structure (traceroute) or reachability (BGP), ABDS combines protocol divergence detection with AS topology correlation to enable automated cause classification—a capability not previously available. Our open-source implementation is available at https: //crates.io/crates/multiprobe. Future work includes largescale measurement via RIPE Atlas and operator ground-truth validation studies.

A

Representative Measurement Data

Table 5 shows 49 representative targets from our dataset spanning all 8 categories, illustrating how ABDS and the 127.0.0.1 signature classify diverse infrastructure deployments.

References [1] B. Augustin, X. Cuvellier, B. Orgogozo, F. Viger, T. Friedman, M. Latapy, C. Magnien, and R. Teixeira. Avoiding traceroute anomalies with Paris traceroute. In Proc. ACM IMC, 2006. [2] E. Katz-Bassett, H. V. Madhyastha, V. K. Adhikari, C. Scott, J. Sherry, P. van Wesep, T. Anderson, and A. Krishnamurthy. Reverse traceroute. In Proc. USENIX NSDI, 2010. [3] S. Kandula, R. Mahajan, P. Verkaik, S. Agarwal, J. Padhye, and P. Bahl. Detailed diagnosis in enterprise networks. In Proc. ACM SIGCOMM, 2009. [4] M. Luckie. Scamper: A scalable and extensible packet prober for active measurement of the Internet. In Proc. ACM IMC, 2010. [5] M. Honda, Y. Nishida, C. Raiciu, A. Greenhalgh, M. Handley, and H. Tokuda. Is it still possible to extend TCP? In Proc. ACM IMC, 2011. [6] C. Kreibich, N. Weaver, B. Nechaev, and V. Paxson. Netalyzr: Illuminating the edge network. In Proc. ACM IMC, 2010. [7] Team Cymru. IP to ASN mapping. https://www.team-cymru.com/ipasn-mapping, 2005. [8] A. Botta and A. Pescape. Dublin Traceroute. https://dublin-traceroute. net, 2016. [9] B. Arzani, S. Ciraci, L. Chamon, Y. Zhu, H. Liu, J. Padhye, B. Loo, and G. Outhred. Taking the blame game out of data centers. In Proc. ACM SIGCOMM, 2016. [10] CAIDA. AS Rank: AS ranking. https://asrank.caida.org, 2019. [11] H. V. Madhyastha, T. Isdal, M. Piatek, C. Dixon, T. Anderson, A. Krishnamurthy, and A. Venkataramani. iPlane: An information plane for distributed services. In Proc. USENIX OSDI, 2006. [12] V. Jacobson. traceroute. ftp://ftp.ee.lbl.gov/traceroute.tar.gz, 1989. [13] R. Beverly. Yarrp’ing the Internet: Randomized high-speed active topology discovery. In Proc. ACM IMC, 2016. [14] K. Vermeulen, J. Rohrer, R. Beverly, O. Gasser, and M. Luckie. DiamondMiner: Comprehensive discovery of the Internet’s topology diamonds. In Proc. USENIX NSDI, 2020. [15] G. Wang, D. G. Andersen, M. Kaminsky, K. Papagiannaki, T. S. E. Ng, M. Kozuch, and M. Ryan. The untold story of data center networks: Analyzing traffic patterns and middlebox interactions. In Proc. ACM IMC, 2011. [16] G. Detal, B. Hesmans, O. Bonaventure, Y. Vanaubel, and B. Donnet. Revealing middlebox interference with tracebox. In Proc. ACM IMC, 2013. [17] B. Hesmans, F. Duchene, C. Paasch, G. Detal, and O. Bonaventure. Are TCP extensions middlebox-proof? In Proc. ACM HotMiddlebox, 2013.

Conference’17, July 2017, Washington, DC, USA [18] M. Allman. On the performance of middleboxes. In Proc. ACM IMC, 2003. [19] N. Weaver, R. Sommer, and V. Paxson. Detecting forged TCP reset packets. In Proc. NDSS, 2009. [20] F. Baker. Requirements for IP Version 4 Routers. RFC 1812, IETF, 1995. [21] L. Gao. On inferring autonomous system relationships in the Internet. IEEE/ACM Transactions on Networking, 9(6):733–745, 2001. [22] M. Luckie, B. Huffaker, A. Dhamdhere, V. Giotsas, and k. claffy. AS relationships, customer cones, and validation. In Proc. ACM IMC, 2013. [23] M. Calder, X. Fan, Z. Hu, E. Katz-Bassett, J. Heidemann, and R. Govindan. Mapping the expansion of Google’s serving infrastructure. In Proc. ACM IMC, 2013.

Biplab Das [24] RIPE NCC Staff. RIPE Atlas: A global Internet measurement network. Internet Protocol Journal, 18(3), 2015. [25] B. Arzani, S. Ciraci, B. T. Loo, A. Schuster, and G. Outhred. 007: Democratically finding the cause of packet drops. In Proc. USENIX NSDI, 2018. [26] E. Katz-Bassett, H. V. Madhyastha, J. P. John, A. Krishnamurthy, D. Wetherall, and T. Anderson. Studying black holes in the Internet with Hubble. In Proc. USENIX NSDI, 2008. [27] M. Zhang, C. Zhang, V. Pai, L. Peterson, and R. Wang. PlanetSeer: Internet path failure monitoring and characterization in wide-area services. In Proc. USENIX OSDI, 2004. [28] ping.pe. Global ping and MTR service. https://ping.pe, 2024.

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation

Conference’17, July 2017, Washington, DC, USA

Table 5: Representative measurement results (49 targets across 8 categories) Target

Category

ABDS

Div Hops

Boundary

127.0.0.1?

Classification

1.1.1.1 8.8.8.8 9.9.9.9 208.67.222.222 94.140.14.14 185.228.168.9 76.76.2.0

Cloud DNS Cloud DNS Cloud DNS Cloud DNS Cloud DNS Cloud DNS Cloud DNS

1.00 0.50 0.00 1.00 0.00 0.00 0.00

2 4 0 1 0 0 0

2 1 0 1 0 0 0

No No No No No No No

Routing policy Mixed No divergence Routing policy No divergence No divergence No divergence

chase.com bankofamerica.com wellsfargo.com citibank.com capitalone.com paypal.com fidelity.com

Finance Finance Finance Finance Finance Finance Finance

0.00 0.00 0.50 1.00 0.44 1.00 0.00

7 0 2 1 9 1 0

0 0 1 1 4 1 0

Yes No No No No No No

Internal (127 sig) No divergence Mixed Routing policy Mixed Routing policy No divergence

irs.gov whitehouse.gov nasa.gov cdc.gov state.gov treasury.gov fbi.gov

Government Government Government Government Government Government Government

0.00 0.00 0.00 0.33 0.00 0.00 0.00

4 0 0 6 0 0 0

0 0 0 2 0 0 0

Yes No No No No No No

Internal (127 sig) No divergence No divergence Internal policy No divergence No divergence No divergence

mit.edu stanford.edu berkeley.edu harvard.edu yale.edu princeton.edu caltech.edu

Education Education Education Education Education Education Education

0.00 0.00 0.00 0.00 0.00 0.00 0.00

1 0 0 0 0 0 0

0 0 0 0 0 0 0

Yes No No No No No No

Internal (127 sig) No divergence No divergence No divergence No divergence No divergence No divergence

zoom.us slack.com akamai.com microsoft.com apple.com netflix.com github.com twitter.com

Tech Tech Tech Tech Tech Tech Tech Tech

0.00 0.08 0.25 0.00 0.00 0.00 0.00 0.40

0 13 4 0 0 0 0 5

0 1 1 0 0 0 0 2

No No No No No No No No

No divergence Internal policy Internal policy No divergence No divergence No divergence No divergence Mixed

amazon.com ebay.com walmart.com target.com shopify.com

E-commerce E-commerce E-commerce E-commerce E-commerce

0.00 0.25 0.00 0.00 0.00

0 8 0 0 0

0 2 0 0 0

No No No No No

No divergence Internal policy No divergence No divergence No divergence

cvs.com anthem.com humana.com cigna.com

Healthcare Healthcare Healthcare Healthcare

0.00 0.00 0.00 0.00

0 0 0 0

0 0 0 0

No No No No

No divergence No divergence No divergence No divergence

bbc.co.uk reuters.com alibaba.com nytimes.com

International International International International

0.00 0.00 0.00 0.00

0 0 0 0

0 0 0 0

No No No No

No divergence No divergence No divergence No divergence

Record · ID 919302 · SHA-256 5cf6360b079b7928
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.