Right the Ship: Assessing the Legitimacy of Invalid Routes in RPKI
Andong Chen, Yangyang Wang, Jia Zhang, Mingwei Xu
Abstract
Resource Public Key Infrastructure (RPKI) aims to prevent prefix hijacking by providing secure mappings between IP prefixes and their authorized origin Autonomous Systems (ASes). In recent years, there has been notable growth in the deployment of RPKI and Route Origin Validation (ROV). Nonetheless, over 40% of the routes in the global routing table still lack the protection of RPKI. One of the critical reasons some networks are reluctant to deploy RPKI is the concern that some ROV-invalid routes may be legitimate, and filtering these routes will harm network service quality, especially affecting network connectivity.
In this work, we perform a comprehensive measurement study to assess the legitimacy of ROV-invalid routes in RPKI. We evaluate the impact of filtering all ROV-invalid routes in the global routing table, presenting a view that some ROV-invalid routes are not illegitimate, defined as harmlessly ROV-invalid (h-invalid). We propose five characteristics and design a characteristics-based methodology for identifying h-invalid routes. Based on the methodology, we analyze the magnitude of h-invalid routes present on the Internet each day, revealing that over 91% of ROV-invalid results are h-invalid. Furthermore, we conclude three main reasons for h-invalid routes. Finally, with all our findings, we provide practical recommendations for network operators to help promote RPKI deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8d05328f-81f9-4249-8b1e-b32dca049d11Builds on12
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- Behind the Scenes of RPKITomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.CCS 2022 · 14 citations
- Themis: Accelerating the Detection of Route Origin Hijacking by Distinguishing Legitimate and Illegitimate MOASLancheng Qin, Dan Li, Ruifeng Li, Kang WangUSENIX Security 2022
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
Related papers
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the InternetTomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael WaidnerUSENIX Security 2023
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan et al.NDSS 2022
- ImpROV: Measurement and Practical Mitigation of Collateral Damage in RPKI Route Origin ValidationWeitong Li, Yuze Li, Taejoong ChungUSENIX Security 2025
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
