BGP-iSec: Improved Security of Internet Routing Against Post-ROV Attacks
Cameron Morris, Amir Herzberg, Bing Wang, Samuel Secondo
Abstract
—We present BGP-iSec, an enhancement of the BGP-sec protocol for securing BGP, the Internet’s inter-domain routing protocol. BGP-iSec ensures additional and stronger security properties, compared to BGPsec, without significant extra overhead. The main improvements are: (i) Security for partial adoption: BGP-iSec provides significant security benefits for early adopters, in contrast to BGPsec, which requires universal adoption. (ii) Defense against route leakage: BGP-iSec defends against route leakage, a common cause of misrouting that is not prevented by BGPsec. (iii) Integrity of attributes: BGP-iSec ensures the integrity of integrity-protected attributes , thereby preventing announcement manipulation attacks not prevented by BGPsec. We argue that BGP-iSec achieves these goals using extensive simulations as well as security analysis. The BGP-iSec design conforms, where possible, with the BGPsec design, modifying it only where necessary to improve security or ease deployment. By providing stronger security guarantees, especially for partial adoption, we hope BGP-iSec will be a step towards finally protecting inter-domain routing, which remains, for many years, a vulnerability of the Internet’s infrastructure.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Suppressing BGP Zombies with Route Status TransparencyYosef Edery Anahory, Jie Kong, Nicholas Scaglione, Justin Furuness et al.NSDI 2025 · 2 citations
- PathProb: Probabilistic Inference and Path Scoring for Enhanced and Flexible BGP Route Leak DetectionYingqian Hao, Hui Zou, Lu Zhou, Yuxuan Chen et al.NDSS 2026 · 1 citation
- ASRogue: Manipulating ASRank-Inferred AS RelationshipsYi Xu, Yihao Chen, Ke Xu, Qi Li et al.USENIX Security 2026
- EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation PoliciesNicholas Scaglione, Justin Furuness, Yossi Gilad, Hemi Leibowitz et al.NSDI 2026
- The CURE to Vulnerabilities in RPKI ValidationDonika Mirdita, Haya Schulmann, Niklas Vogel, Michael WaidnerNDSS 2024
Builds on10
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- SICO: Surgical Interception Attacks by Manipulating BGP CommunitiesHenry Birge-Lee, Liang Wang, Jennifer Rexford, Prateek MittalCCS 2019 · 51 citations
- The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet ResourcesTianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael WaidnerUSENIX Security 2021 · 22 citations
- Beyond Limits: How to Disable Validators in Secure NetworksTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann et al.SIGCOMM 2023 · 14 citations
- MoSS: Modular Security Specifications FrameworkAmir Herzberg, Hemi Leibowitz, Ewa Syta, Sara WrótniakCRYPTO 2021 · 2 citations
Related papers
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya et al.NDSS 2025
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti et al.NSDI 2024 · 21 citations
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
- The Ivory Tower Syndrome: Operators' Reflections on Academic BGP Security SolutionsAleeza Suhel Inamdar, Tobias Fiebig, Mannat KaurUSENIX Security 2026
