USENIX Security2026Top-tier venue
iROV: Breaking the Silence of RPKI with Interactive Validation
Younsoo Kim, Seungjin Baek, Weitong Li, Tijay Chung, Min Suk Kang
Abstract
While Route Origin Validation (ROV) effectively mitigates prefix hijacking, it drops BGP updates that are inconsistent with currently published ROAs without consulting the prefix owner. This silent-drop behavior creates a serious agility gap: when a resource owner must urgently redirect traffic during DDoS mitigation, the temporary route may deviate from the currently published ROAs and be dropped before a ROA update propagates. We propose iROV (interactive ROV), a lightweight extension to ROV, to address the agility gap by transforming validation from a static local decision into an interactive, owner-involved process. iROV enables routers to query prefix owners for "Just-in-Time" authorization of invalid routes. This interactivity also allows prefix owners to receive real-time visibility feedback on ROV-invalidation events, which helps them detect remote prefix-hijacking attempts or quickly discover their own benign misconfigurations. To mitigate availability threats introduced by this interactivity, iROV employs validity stapling to suppress redundant queries, and probabilistic querying to bound owner-side query load. Large-scale simulations and a prototype implementation demonstrate that iROV restores reachability for urgent route changes from 23% to up to nearly 90%, and delivers rapid feedback on anomalies with granular impact estimation, while incurring negligible overhead.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on7
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira et al.NDSS 2017 · 108 citations
- Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the InternetTomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael WaidnerUSENIX Security 2023
- The Threat Landscape of IP Leasing in the RPKI EraWeitong Li, Yongzhe Xu, Taejoong ChungS&P 2026
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV DeploymentWenqi Chen, Zhiliang Wang, Dongqi Han, Chenxin Duan et al.NDSS 2022
Related papers
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin et al.NDSS 2021
- Understanding Route Origin Validation (ROV) Deployment in the Real World and Why MANRS Action 1 Is Not FollowedLancheng Qin, Li Chen, Dan Li, Honglin Ye et al.NDSS 2024
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya et al.NDSS 2025
- From Address Blocks to Authorized Prefixes: Redesigning RPKI ROV with a Hierarchical Hashing Scheme for Fast and Memory-Efficient ValidationZedong Ni, Yinbo Xu, Hui Zou, Yanbiao Li et al.NSDI 2025 · 3 citations
- ImpROV: Measurement and Practical Mitigation of Collateral Damage in RPKI Route Origin ValidationWeitong Li, Yuze Li, Taejoong ChungUSENIX Security 2025
