Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security Risks
Weitong Li, Tao Wan, Tijay Chung
Abstract
—The Resource Public Key Infrastructure (RPKI) enhances Internet routing security by utilizing Route Origin Authorization ( ROA ) objects to link IP prefixes with their rightful origin ASNs. Despite the rapid deployment of RPKI—over 51.3% of Internet routes now covered by ROAs , there are still 6,802 RPKI-invalid prefixes as of today. This work provides the first comprehensive study to understand and classify the hidden causes of RPKI-invalid prefixes, revealing that ROA misconfigurations often occur during IP leasing and IP transit services. We identify scenarios explaining these misconfigurations and attribute 96.9% of the RPKI-invalid prefixes to such misconfigurations. We further show their cascading impacts on the data-plane, noting that while most prefixes exhibit negligible effects, 3.1% result in full connectivity loss and 7.1% degrade routing by adding latency and extra hop counts—and, in some cases, also bypassing intended security mechanisms; additionally, we find that such misconfigurations have been triggering false alarms in hijack detection systems. To validate our findings, we build a ground-truth dataset of 294 misconfigured prefixes through direct engagement with 174 network operators. We also interviewed 16 large ISPs and major leasing brokers about their ROA management practices, and we propose suggestions to avert ROA misconfigurations. Taken together, this study not only fills gaps left by previous research but also offers actionable recommendations to network operators for improving ROA management and minimizing the occurrence of RPKI-invalid announcements.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 82e592f3-f40c-4b61-b3fd-c7d4b31477f1Cited by top-tier papers1
Ask how each one uses itBuilds on2
- Themis: Accelerating the Detection of Route Origin Hijacking by Distinguishing Legitimate and Illegitimate MOASLancheng Qin, Dan Li, Ruifeng Li, Kang WangUSENIX Security 2022
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
Related papers
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Right the Ship: Assessing the Legitimacy of Invalid Routes in RPKIAndong Chen, Yangyang Wang, Jia Zhang, Mingwei XuCCS 2025
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
- The Hanging ROA: A Secure and Scalable Encoding Scheme for Route Origin AuthorizationYanbiao Li, Hui Zou, Yuxuan Chen, Yinbo Xu et al.INFOCOM 2022 · 6 citations
- The Threat Landscape of IP Leasing in the RPKI EraWeitong Li, Yongzhe Xu, Taejoong ChungS&P 2026
