Skip to main content
QUICK REVIEW

[论文解读] Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet

Tomáš Hlaváček, Haya Shulman|arXiv (Cornell University)|Mar 21, 2023
Network Security and Intrusion Detection被引用 4
一句话总结

本文通过在全球互联网范围内使用改进的控制平面与数据平面测量,评估了RPMI部署及其在阻止BGP前缀劫持方面的有效性。研究发现,超过27%的AS实施了RPMI过滤,主要由大型运营商出于商业激励驱动;而互联网交换点(IXP)路由服务器仅提供局部保护,无法阻止全球劫持传播——凸显了一流运营商在全球安全中的关键作用。

ABSTRACT

IP prefix hijacks allow adversaries to redirect and intercept traffic, posing a threat to the stability and security of the Internet. To prevent prefix hijacks, networks should deploy RPKI and filter bogus BGP announcements with invalid routes. In this work we evaluate the impact of RPKI deployments on the security and resilience of the Internet. We aim to understand which networks filter invalid routes and how effective that filtering is in blocking prefix hijacks. We extend previous data acquisition and analysis methodologies to obtain more accurate identification of networks that filter invalid routes with RPKI. We find that more than 27% of networks enforce RPKI filtering and show for the first time that deployments follow the business incentives of inter-domain routing: providers have an increased motivation to filter in order to avoid losing customers' traffic. Analyzing the effectiveness of RPKI, we find that the current trend to deploy RPKI on routeservers of Internet Exchange Points (IXPs) only provides a localized protection against hijacks but has negligible impact on preventing their spread globally. In contrast, we show that RPKI filtering in Tier-1 providers greatly benefits the security of the Internet as it limits the spread of hijacks to a localized scope. Based on our observations, we provide recommendations on the future roadmap of RPKI deployment. We make our datasets available for public use [https://sit4.me/rpki].

研究动机与目标

  • 以高于以往研究的精度测量互联网中路由源验证(ROV)的当前部署率。
  • 理解不同类型自治系统(ASes)在ROV采用方面的商业与技术激励因素。
  • 评估RPMI过滤在防止无效BGP路由全球传播方面的有效性,特别比较IXP路由服务器与一流运营商的差异。
  • 评估在IXP路由服务器上部署RPMI是否能对前缀劫持提供有意义的全球保护。
  • 基于网络拓扑与安全影响,为未来RPMI部署提供可操作的建议。

提出的方法

  • 使用RIPE Atlas进行控制平面与数据平面测量,通过注入模拟前缀劫持的无效ROA来检测ROV实施情况。
  • 将BGP路由表变化与实际流量路径相关联,以区分实施ROV的AS与未受无效宣告影响的AS。
  • 实施改进的数据采集与分析方法,相比以往方法显著降低误报与漏报。
  • 构建并分析不同网络类型(IXPs、直接对等、一流运营商)间无效路由的传播图,以评估可达性与传播范围。
  • 使用图论指标(如代数连通性与最短路径长度)量化ROV对路由传播的影响。
  • 按类型(如运营商、末端网络、IXPs)对AS进行分类,并将ROV实施与商业激励及网络角色相关联。

实验结果

研究问题

  • RQ1互联网中RPMI路由源验证(ROV)的当前部署率是多少?其演变趋势如何?
  • RQ2哪些网络类型(如运营商、末端网络、IXPs)最有可能实施ROV?其决策背后的商业激励是什么?
  • RQ3在IXP路由服务器上部署RPMI在多大程度上能阻止无效BGP路由的全球传播?
  • RQ4与其它网络类型相比,一流运营商中ROV实施在限制劫持传播范围方面的有效性如何?
  • RQ5ROV对互联网路由基础设施韧性的全球影响是什么?

主要发现

  • 目前互联网中超过27%的自治系统(ASes)实施了RPMI过滤,以阻止无效BGP宣告。
  • ROV部署与商业激励高度一致:大型运营商和ISP更可能实施ROV,以避免客户流量与收入损失。
  • IXP路由服务器仅能提供针对劫持的局部保护,因为IXP上的直接对等会话会将无效路由全球传播,绕过ROV过滤。
  • 顶级IXP(如AMS-IX、DE-CIX)中直接对等会话的普遍性使无效路由传播速度提升3.4倍,削弱了全球保护效果。
  • 在一流运营商中实施ROV是限制劫持全球传播最有效的机制,因其在路由层级中天然充当关键瓶颈。
  • 图分析表明,尽管路由服务器减少了无效更新的本地连通性,但并未显著限制最大传播范围——无效路径仍可通过直接会话与全球运营商广泛传播。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。