Loading…
Attending this event?
Saturday September 21, 2024 5:05pm - 5:35pm EDT

Link to paper

Abstract:
Although Internet routing security best practices have recently seen auspicious increases in uptake, ISPs have limited incentives to deploy them. They are operationally complex and expensive to implement and provide little competitive advantage. The practices with significant uptake protect only against origin hijacks, leaving unresolved the more general threat of path hijacks. We propose a new approach to improved routing security that achieves four design goals: improved incentive alignment to implement best practices; protection against path hijacks; expanded scope of such protection to customers of those engaged in the practices; and reliance on existing capabilities rather than needing complex new software in every participating router. Our proposal leverages an existing coherent core of interconnected ISPs to create a zone of trust, a topological region that protects not only all networks in the region, but all directly attached customers of those networks. Customers benefit from choosing ISPs committed to the practices, and ISPs thus benefit from committing to the practices. We discuss the concept of a zone of trust as a new, more pragmatic approach to security, that improves security in a region of the Internet, as opposed to striving for a global improvement. We argue that the aspiration for global improvement is unrealistic, since the global Internet includes malicious actors. We compare our approach to other schemes, and discuss how a related proposal, ASPA, could be used to increase the scope of protection our scheme achieves. We hope this proposal inspires discussion of how the industry can make practical, measurable progress against the threat of route hijacks in the short term by leveraging institutionalized cooperation rooted in transparency and accountability.
Authors
CT

Cecilia Testart

Georgia Institute of Technology
ML

Matthew Luckie

CAIDA/UCSD
KC

kc claffy

CAIDA/UCSD
Discussants
VS

Volker Stocker

Weizenbaum Institute for the Networked Society
Saturday September 21, 2024 5:05pm - 5:35pm EDT
Room Y116 WCL, 4300 Nebraska Ave, Washington, DC

Attendees (7)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link