用大模型自动分析并报告BGP异常事件,提升网络运维效率。
BEAR: BGP Event Analysis and Reporting
- 通过多步推理将表格化的BGP数据转为文字报告
- 在真实与合成数据上实现100%检测准确率
- 适合网络管理员和安全团队快速理解复杂路由异常
互联网由相互连接、独立管理的自治系统(AS)组成,依赖边界网关协议(BGP)进行域间路由。BGP异常(如路由泄露和劫持)可能导致流量经由未经授权或低效路径,威胁网络可靠性与安全。现有基于规则和机器学习的方法虽能检测异常,但仍需具备深入BGP知识的专家解读事件并提出修复方案。本文提出BEAR(BGP事件分析与报告)框架,利用大语言模型(LLM)自动生成详尽的异常事件解释报告。BEAR采用多步推理流程,将结构化BGP数据转化为详细文本叙述,提升可解释性与分析精度。为解决公开可用的BGP异常数据稀缺问题,我们还提出一个基于LLM的合成数据生成框架。在真实与合成数据集上的评估表明,BEAR达到100%准确率,优于链式思维与上下文学习基线。该工作开创了自动化解释BGP异常事件的新范式,为网络管理提供关键运营洞察。
原文摘要 · Abstract (English)
The Internet comprises of interconnected, independently managed Autonomous Systems (AS) that rely on the Border Gateway Protocol (BGP) for inter-domain routing. BGP anomalies--such as route leaks and hijacks--can divert traffic through unauthorized or inefficient paths, jeopardizing network reliability and security. Although existing rule-based and machine learning methods can detect these anomalies using structured metrics, they still require experts with in-depth BGP knowledge of, for example, AS relationships and historical incidents, to interpret events and propose remediation. In this paper, we introduce BEAR (BGP Event Analysis and Reporting), a novel framework that leverages large language models (LLMs) to automatically generate comprehensive reports explaining detected BGP anomaly events. BEAR employs a multi-step reasoning process that translates tabular BGP data into detailed textual narratives, enhancing interpretability and analytical precision. To address the limited availability of publicly documented BGP anomalies, we also present a synthetic data generation framework powered by LLMs. Evaluations on both real and synthetic datasets demonstrate that BEAR achieves 100% accuracy, outperforming Chain-of-Thought and in-context learning baselines. This work pioneers an automated approach for explaining BGP anomaly events, offering valuable operational insights for network management.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。