Paper 2016/1010

Are We There Yet? On RPKI's Deployment and Security

Yossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira, and Haya Shulman

Abstract

The Resource Public Key Infrastructure (RPKI) binds IP address blocks to owners’ public keys. RPKI enables routers to perform Route Origin Validation (ROV), thus preventing devastating attacks such as IP prefix hijacking. Yet, despite extensive effort, RPKI’s deployment is frustratingly sluggish, leaving the Internet largely insecure. We tackle fundamental questions regarding today’s RPKI’s deployment and security: What is the adoption status of RPKI and ROV? What are the implications for global security of partial adoption? What are the root-causes for slow adoption? How can deployment be pushed forward? We address these questions through a combination of empirical analyses, a survey of over 100 network practitioners, and extensive simulations. Our main contributions include the following.We present the first study measuring ROV enforcement, revealing disappointingly low adoption at the core of the Internet. We show, in contrast, that without almost ubiquitous ROV adoption by large ISPs significant security benefits cannot be attained. We next expose a critical security vulnerability: about a third of RPKI authorizations issued for IP prefixes do not protect the prefix from hijacking attacks. We examine potential reasons for scarce adoption of RPKI and ROV, including human error in issuing RPKI certificates and inter-organization dependencies, and present recommendations for addressing these challenges.

Note: Technical report version (updated after original publication)

Metadata
Available format(s)
PDF
Publication info
Published elsewhere. NDSS 2017
Keywords
Routing securitypublic key infrastructure
Contact author(s)
yossig2 @ gmail com
History
2017-09-05: last of 11 revisions
2016-10-26: received
See all versions
Short URL
https://ia.cr/2016/1010
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2016/1010,
      author = {Yossi Gilad and Avichai Cohen and Amir Herzberg and Michael Schapira and Haya Shulman},
      title = {Are We There Yet? On RPKI's Deployment and Security},
      howpublished = {Cryptology ePrint Archive, Paper 2016/1010},
      year = {2016},
      note = {\url{https://eprint.iacr.org/2016/1010}},
      url = {https://eprint.iacr.org/2016/1010}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.