Practical experience: Methodologies for measuring route origin validation

Tomas Hlavacek, Amir Herzberg, Haya Shulman, Michael Waidner

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

15 Scopus citations

Abstract

Performing Route Origin Validation (ROV) to filter BGP announcements, which contradict Route Origin Authorizations (ROAs) is critical for protection against BGP prefix hijacks. Recent works quantified ROV enforcing Autonomous Systems (ASes) using control-plane experiments. In this work we show that control-plane experiments do not provide accurate information about ROV-enforcing ASes. We devise data-plane approaches for evaluating ROV in the Internet and perform both control and data-plane experiments using different data acquisition sources. We analyze and correlate the results of our study to identify the number of ASes enforcing ROV, and hence protected with RPKI. We perform simulations with the ROV-enforcing ASes that we identified, and find that their impact on the Internet security against prefix hijacks is negligible. As a countermeasure we provide recommendations how to cope with the main factor hindering wide adoption of ROV.

Original languageEnglish
Title of host publicationProceedings - 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2018
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages634-641
Number of pages8
ISBN (Electronic)9781538655955
DOIs
StatePublished - 19 Jul 2018
Externally publishedYes
Event48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2018 - Luxembourg City, Luxembourg
Duration: 25 Jun 201828 Jun 2018

Publication series

NameProceedings - 48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2018

Conference

Conference48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2018
Country/TerritoryLuxembourg
CityLuxembourg City
Period25/06/1828/06/18

Bibliographical note

Funding Information:
We thank Hank Nussbacher, Israel Inter-University Computation Center for setting up the experiment and providing measured data. The research reported in this paper has been supported in part by the German Federal Ministry of Education and Research (BMBF), by the Hessian Ministry of Science and the Arts within CRISP (www.crisp-da.de/) and co-funded by the DFG as part of project S3 within the CRC 1119 CROSSING.

Publisher Copyright:
© 2018 IEEE.

Keywords

  • BGP
  • Controlled Experiments
  • ROV
  • RPKI
  • Route Origin Validation

Fingerprint

Dive into the research topics of 'Practical experience: Methodologies for measuring route origin validation'. Together they form a unique fingerprint.

Cite this