FP7Reintegration grant2012–2016

SIRENS · Securing Internet Routing: Economics vs. Network Security

FP7 — People (Marie Curie Actions)

Duration
2012-10-01 → 2016-09-30
EU contribution
€100,000
Participants
1
Scheme
MC-CIG

Lines connect the coordinator with its partners.

Results in brief

Securing Internet Routing: Economics vs. Network Security

On June 12, 2015, an incident in the Asia-Pacific region caused network performance problems for hundreds of thousands of Internet destinations, including Facebook and Amazon.24,37 It was not the result of a natural disaster, a failed transatlantic cable, or a malicious attack. Instead, it resulted from a misconfiguration at a Malaysian ISP that inadvertently exploited the Internet's Border Gateway Protocol (BGP) to disrupt connectivity at networks in Malaysia and beyond. BGP establishes Internet connectivity by setting up routes between independently operated networks. Over the past two decades, several high-profile routing incidents (often resulting from misconfigurations) have regularly demonstrated that BGP is highly vulnerable to malicious attacks. BGP attacks cause a victim network Internet traffic to be rerouted to the attacker's own network. The rerouted traffic might then be dropped before it reaches its legitimate destination or, more deviously, be subject to eavesdropping, traffic analysis, or tampering. To deal with these vulnerabilities, the Internet community has spent almost two decades considering a variety of protocols for securing BGP. Today, however, Internet routing remains largely unprotected by BGP security protocols. The sluggish deployment of BGP security is the result of economic, operational, and policy challenges. The root cause for this situation is that the Internet lacks a single authority that can mandate deployment of BGP security upgrades. Deployment decisions are instead made by independently operated networks according to their own local policy and business objectives. BGP security is adopted by a network only if its security benefits are thought to justify its deployment and operational costs. Moreover, the diversity of BGP security protocols has led to some controversy as to which protocol should actually be deployed. This issue is exacerbated by the fact that each protocol offers different security benefits and comes with different costs. My CIG-funded research focused on identifying the obstacles facing the realisation of today's agenda for securing BGP routing (as advocated, e.g., by the Internet Engineering Task Force). I tackled the following questions: What is the adoption status of BGP security? What are the implications for global security of partial adoption? What are the root-causes for slow adoption? How can deployment be pushed forward? I addressed these questions through a combination of theoretical and empirical analyses, surveys of many network practitioners, and extensive simulations. The results of this project exposed severe obstacles facing today's approach to securing routing on the Internet, including lack of sufficient value for early adopters, resulting in the classical chicken and egg problem facing the deployment of new Internet protocols (little incentive to adopt until many others have already adopted). To remedy this, my research proposed guidelines for engineering the deployment process in an incentive-oriented manner so as to drive deployment forward. My co-authors and I also proposed an easily deployable and modest extension to today's approach, called “path-end validation”, which can significantly enhance routing security. We showed, through rigorous security analyses and extensive simulations on empirically derived datasets, that path-end validation yields significant benefits even in very limited partial adoption. We presented an open-source, readily deployable prototype implementation of path-end validation.

Data: CORDIS, © European Union

Project objective

The Internet is made up of over 35,000 smaller networks, owned by different economic entities (e.g., AT&T, Google). The Border Gateway Protocol (BGP) establishes routes between these networks and can be regarded as the “glue” that holds today’s Internet together.BGP was designed at a time when the Internet was meant to provide connectivitybetween largely trusted and cooperative parties. However, times have changed and today’s BGPis notoriously vulnerable to attacks. To remedy this, secure variants of BGP have been proposed to prevent the propagation of bogus routing information. Unfortunately, despite a decade of extensive work the problem of securing the Internet’s interdomain routing is far from solved and deployment of a secure routing protocol is not on the horizon.It is now clear that the two biggest impediments on the path to secure Internet routing are:1. Which secure protocol to deploy? There are still lingering disagreementsabout which of the security-enhanced variants of BGP should be deployed.2. How to create economic incentives for deployment? Even once an agreement about which secure BGP variant to deploy will be reached, how can we get the ball rolling on protocol deployment?My proposed research aims to inform this discussion and will consist of three main components: (1) investigating the security guarantees of the major proposed secure BGP variants; (2) exploring the vulnerabilities of the routing system to new kinds of attacks; and (3) designing market mechanisms for large-scale deployment of a secure routing protocol.To achieve these goals, I plan to combine theoretical analysis with extensive simulations on real-life data. AIongside its practical contributions, the proposed research will involve posing and tackling new and exciting theoretical questions, motivated by Internet routing (topics on the borderline of distributed computing and game theory, non-local influence in social neworks, and more).

Original text from CORDIS.

Participants

  • THE HEBREW UNIVERSITY OF JERUSALEM · JerusalemCoordinatorIsrael

Links

Data: CORDIS, © European Union