2026-doumanidis-howlr-client-driven-approach
HOWLR: A Client-Driven Approach to BGP Hijack Detection
canonical link → · arxiv: 2606.21845
2026-doumanidis-howlr-client-driven-approach
canonical link → · arxiv: 2606.21845
findings extracted from this paper
HOWLR successfully detects 83% of the 1,902 real-world prefix hijack incidents observed in high-confidence Cloudflare Radar data from May 2026. The detection method fails when the hijacked prefix contains no authenticatable witnesses, and also cannot defend against routing adversaries capable of transparently forwarding non-targeted traffic within the prefix.
HOWLR's T4 variant (scanning only port 443) reduces worst-case prefix scan time from 260 minutes to 4 minutes while missing fewer than 2 witnesses in 83.6% of prefixes; the worst-case drop was 13 witnesses in a high-density prefix, still leaving 15 usable witnesses. Over a 6-day monitoring period, 96% of the 30,217-witness set maintained 99+% uptime.
HOWLR provides Light protection (≥3 witnesses in prefix) to 89% of Tor relay prefixes and Strong protection (≥8 witnesses from ≥2 CAs) to 64%, based on sampling 200 random relays. By contrast, DNS server prefixes receive Light protection in only 40% and Strong protection in only 12% of cases, reflecting their tendency toward residential or sparse hosting.
BGP hijacking remains a practical threat to circumvention infrastructure: BGPWatch reported 5,673 possible hijack events in 2024 alone, and approximately 43% of ASes currently do not enforce route origin validation, leaving RPKI-covered prefixes still vulnerable. An attacker can statistically divert 50% of traffic by announcing an equally specific prefix with the genuine origin and itself prepended as next hop.
All sampled popular-service prefixes contain at least two TLS-authenticated witnesses, and more than half contain 35 or more witnesses; by contrast, only 40% of randomly selected prefixes feature any valid witnesses. CT log analysis across 5 months shows that witnesses span just 17.4% of the routable IPv4 space, confirming that witness coverage concentrates on professionally-hosted infrastructure.