Publications

Smart RPKI Validation: Avoiding Errors and Preventing Hijacks

AuthorHlavacek, Tomas; Schulmann, Haya; Waidner, Michael
Date2022
TypeConference Proceedings
Abstract"Resource Public Key Infrastructure (RPKI) was designed to authorize ownership of prefixes in the Internet, which routers use to filter bogus BGP announcements to prevent prefix hijacks. Although already 360K routes have valid covering Route Origin Authorizations (ROAs), RPKI is not widely validated. Erroneous ROAs are one of the obstacles towards wide filtering of bogus BGP announcements with Route Origin Validation (ROV). Erroneous ROAs conflict with BGP announcements and appear similar to hijacking announcements. Blocking such conflicting announcements can disconnect networks and hence demotivates enforcement of ROV."
Isbn978-3-031-17140-6
InComputer Security — ESORICS 2022, p.509-530
PublisherSpringer
Partnhlavacek2022smartrpki