• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. DISCO: Sidestepping RPKI's Deployment Barriers
 
  • Details
  • Full
Options
2020
Conference Paper
Title

DISCO: Sidestepping RPKI's Deployment Barriers

Abstract
BGP is a gaping security hole in todays Internet, as evidenced by numerous Internet outages and blackouts, repeated traffic hijacking, and surveillance incidents. To protect against prefix hijacking, the Resource Public Key Infrastructure (RPKI) has been standardized. Yet, despite Herculean efforts, ubiquitous deployment of the RPKI remains distant, due to RPKIs manual and error-prone certification process. We argue that deploying origin authentication at scale requires substituting the standard requirement of certifying legal ownership of IP address blocks with the goal of certifying de facto ownership. We show that settling for de facto ownership is sufficient for protecting against hazardous prefix hijacking and can be accomplished without requiring any changes to todays r outing infrastructure. We present DISCO, a readily deployable system that automatically certifies de facto ownership and generates the appropriate BGP path-filtering rules at routers. We evaluate DISCOs security and deployability via live experiments on the Internet using a prototype implementation of DISCO and through simulations on empirically-derived datasets. To facilitate the reproducibility of our results, we open source our prototype, simulator, and measurement analysis code [30].
Author(s)
Hlavacek, Tomas  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Cunha, Italo
Universidade Federal de Minas Gerais; Columbia University
Gilad, Yossi
Hebrew University of Jerusalem
Herzberg, Amir
University of Connecticut
Katz-Bassett, Ethan
Columbia University
Schapira, Michael
Hebrew University of Jerusalem
Shulman, Haya  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Mainwork
Network and Distributed Systems Security Symposium, NDSS 2020. Proceedings. Online resource  
Conference
Network and Distributed Systems Security Symposium (NDSS) 2020  
DOI
10.14722/ndss.2020.24355
Additional full text version
Landing Page
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024