From the Consent of the Routed: Improving the Transparency of the RPKI

被引:2
作者
Heilman, Ethan [1 ]
Cooper, Danny [1 ]
Reyzin, Leonid [1 ]
Goldberg, Sharon [1 ]
机构
[1] Boston Univ, Dept Comp Sci, 111 Cummington St, Boston, MA 02215 USA
来源
SIGCOMM'14: PROCEEDINGS OF THE 2014 ACM CONFERENCE ON SPECIAL INTEREST GROUP ON DATA COMMUNICATION | 2014年
基金
美国国家科学基金会;
关键词
BGP; HIJACKING; SECURITY;
D O I
10.1145/2619239.2626293
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Resource Public Key Infrastructure (RPKI) is a new infrastructure that prevents some of the most devastating attacks on interdomain routing. However, the security benefits provided by the RPKI are accomplished via an architecture that empowers centralized authorities to unilaterally revoke any IP prefixes under their control. We propose mechanisms to improve the transparency of the RPKI, in order to mitigate the risk that it will be used for IP address takedowns. First, we present tools that detect and visualize changes to the RPKI that can potentially take down an IP prefix. We use our tools to identify errors and revocations in the production RPKI. Next, we propose modifications to the RPKI's architecture to (1) require any revocation of IP address space to receive consent from all impacted parties, and (2) detect when misbehaving authorities fail to obtain consent. We present a security analysis of our architecture, and estimate its overhead using data-driven analysis.
引用
收藏
页码:51 / 62
页数:12
相关论文
共 55 条
[1]  
Aiello W., 2003, PROC 10 ACM C COMPUT, P165
[2]  
Amante S., 2012, RISKS ASS RESOURCE C
[3]  
Anderson D, 2012, QUEUE, V10, P40
[4]  
[Anonymous], 2011, SOVEREIGN KEY CRYPTO
[5]  
Austein R., 2012, 6486 RFC
[6]   A study of prefix hijacking and interception in the Internet [J].
Ballani, Hitesh ;
Francis, Paul ;
Zhang, Xinyang .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2007, 37 (04) :265-276
[7]  
Bush R., 2013, RPKI LOCAL TRUST ANC
[8]  
Bush R., 2012, RPKI BASED ORIGIN VA
[9]  
Bush R., 2012, RESPONSIBLE GRANDPAR
[10]  
Butler K, 2010, P IEEE, V98, P100, DOI 10.1109/JPROC.2009.2034031