Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet
IP prefix hijacks allow adversaries to redirect and intercept traffic, posing a threat to the stability and security of the Internet. To prevent prefix hijacks, networks should deploy RPKI and filter bogus BGP announcements with invalid routes. In this work we evaluate the impact of RPKI deployments...
Saved in:
Main Authors: | , , , |
---|---|
Format: | Journal Article |
Language: | English |
Published: |
21-03-2023
|
Subjects: | |
Online Access: | Get full text |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Summary: | IP prefix hijacks allow adversaries to redirect and intercept traffic, posing
a threat to the stability and security of the Internet. To prevent prefix
hijacks, networks should deploy RPKI and filter bogus BGP announcements with
invalid routes.
In this work we evaluate the impact of RPKI deployments on the security and
resilience of the Internet. We aim to understand which networks filter invalid
routes and how effective that filtering is in blocking prefix hijacks. We
extend previous data acquisition and analysis methodologies to obtain more
accurate identification of networks that filter invalid routes with RPKI. We
find that more than 27% of networks enforce RPKI filtering and show for the
first time that deployments follow the business incentives of inter-domain
routing: providers have an increased motivation to filter in order to avoid
losing customers' traffic.
Analyzing the effectiveness of RPKI, we find that the current trend to deploy
RPKI on routeservers of Internet Exchange Points (IXPs) only provides a
localized protection against hijacks but has negligible impact on preventing
their spread globally. In contrast, we show that RPKI filtering in Tier-1
providers greatly benefits the security of the Internet as it limits the spread
of hijacks to a localized scope. Based on our observations, we provide
recommendations on the future roadmap of RPKI deployment.
We make our datasets available for public use [https://sit4.me/rpki]. |
---|---|
DOI: | 10.48550/arxiv.2303.11772 |