EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation Policies
Nicholas Scaglione, Justin Furuness, Yossi Gilad, Hemi Leibowitz, Cameron Morris, Bing Wang, Kotikalapudi Sriram, Amir Herzberg
Abstract
The lack of Source Address Validation (SAV) is a significant vulnerability of the Internet, which is abused in many Denial-of-Service (DoS) and other attacks. Several IETF RFCs define easy-to-deploy, non-interactive SAV designs; the IETF is currently developing another SAV mechanism, BAR-SAV, which, as its name suggests, uses BGP, ASPA (Autonomous System Provider Authorization), and ROA (Route Origin Authorization) data. However, no comparative evaluation of the potential impact of their large-scale deployment has been done. A recent survey of network vendors and operators indicates that more efficacy data and usage guidelines are necessary to motivate their adoption.
We present EZ-SAVE, the first simulation-based analysis evaluating easy-to-deploy SAV policies. We measure both the spoofed traffic detection rates and the legitimate traffic filtering (false-positive) rates for each standard and proposed design at different adoption rates, using a realistic Internet topology and traffic engineering policies. Our results reveal several significant insights that may assist and guide the standardization process as well as developers and operators. In particular, we find that BAR-SAV proves to be the most effective design that features high spoof detection rates and low (or even zero) false-positive rates, motivating its standardization and deployment. Our results also provide operators with guidance on other SAV mechanisms that are effective for specific scenarios. In addition, our results highlight the importance of using realistic export policies for SAV evaluation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 932a87a1-790d-4d08-9541-28d9d262ae96Cited by top-tier papers1
Ask how each one uses itBuilds on8
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Network Hygiene, Incentives, and Regulation: Deployment of Source Address Validation in the InternetMatthew J. Luckie, Robert Beverly, Ryan Koga, Ken Keys et al.CCS 2019 · 89 citations
- Deployment of Source Address Validation by Network Operators: A Randomized Control TrialQasim Lone, Alisa Frik, Matthew Luckie, Maciej Korczynski et al.S&P 2022 · 16 citations
- Suppressing BGP Zombies with Route Status TransparencyYosef Edery Anahory, Jie Kong, Nicholas Scaglione, Justin Furuness et al.NSDI 2025 · 2 citations
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
Related papers
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya et al.NDSS 2025
- OSAVRoute: Advancing Outbound Source Address Validation Deployment Detection with Non-Cooperative MeasurementShuai Wang, Ruifeng Li, Li Chen, Dan Li et al.NDSS 2026 · 3 citations
- Aliens Among Us: Observing Private or Reserved IPs on the Public InternetRadu Anghel, Carlos Gañán, Qasim Lone, Matthew Luckie et al.NDSS 2026
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan et al.NDSS 2022
- Your Router is My Prober: Measuring IPv6 Networks via ICMP Rate Limiting Side ChannelsLong Pan, Jiahai Yang, Lin He, Zhiliang Wang et al.NDSS 2023
