paper

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation

arXiv:2609.14835

Abstract

Network operators frequently encounter protocol divergence---where ICMP, TCP, and UDP experience different treatment along a path. Existing tools identify where divergence occurs but not why, forcing manual investigation that delays resolution. We present two contributions: (1) the AS-Boundary Divergence Score (ABDS), a metric that correlates protocol divergence locations with BGP topology to automatically classify causes as routing-policy-driven versus internal-policy-driven; and (2) the localhost response signature, an empirical finding that security appliances return 127.0.0.1 in TTL-exceeded messages to mask their IPs. We evaluate ABDS against 496 targets across 8 categories (Finance, Government, Education, Healthcare, Tech, E-commerce, Media, International), with multi-vantage validation from 10+ global locations confirming routing consistency. ABDS achieves 100% classification accuracy on verified divergent targets (50/50), significantly outperforming majority-class baseline (54%, McNemar's p < 0.001). The localhost signature achieves 100% precision (18/18, 95% CI: [82%, 100%]) in identifying security appliances across 9 categories including government (IRS, USPS, VA), finance, and healthcare. Our open-source Rust implementation enables automated escalation decisions, reducing mean-time-to-resolution for network operators.

8 pages, 3 figures, 7 tables. Under review at IEEE Transactions on Network and Service Management (TNSM). Manuscript ID: TNSM-2026-12196

ABDS: Classifying Protocol Divergence Causes via AS-Boundary Correlation · wovepaper