Flexsealing BGP Against Route Leaks: Peerlock Active Measurement and Analysis
Tyler McDaniel, Jared M. Smith, Max Schuchard
摘要
BGP route leaks frequently precipitate serious disruptions to interdomain routing. These incidents have plagued the Internet for decades while deployment and usability issues cripple efforts to mitigate the problem. Peerlock, introduced in 2016, addresses route leaks with a new approach. Peerlock enables filtering agreements between transit providers to protect their own networks without the need for broad cooperation or a trust infrastructure. We outline the Peerlock system and one variant, Peerlock-lite, and conduct live Internet experiments to measure their deployment on the control plane. Our measurements find evidence for significant Peerlock protection between Tier 1 networks in the peering clique, where 48% of potential Peerlock filters are deployed, and reveal that many other networks also deploy filters against Tier 1 leaks. To guide further deployment, we also quantify Peerlock's impact on route leaks both at currently observed levels and under hypothetical future deployment scenarios via BGP simulation. These experiments reveal present Peerlock deployment restricts Tier 1 leak export to 10% or fewer networks for 40% of simulated leaks. Strategic additional Peerlock-lite deployment at all large ISPs (fewer than 1% of all networks), in tandem with Peerlock within the peering clique as deployed, completely mitigates 80% of simulated Tier 1 route leaks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- PathProb: Probabilistic Inference and Path Scoring for Enhanced and Flexible BGP Route Leak DetectionYingqian Hao, Hui Zou, Lu Zhou, Yuxuan Chen 等NDSS 2026 · 被引用 1 次
- Anycast Agility: Network Playbooks to Fight DDoSA. S. M. Rizvi, Leandro M. Bertholdo, João M. Ceron, John S. HeidemannUSENIX Security 2022
- Understanding the Stealthy BGP Hijacking Risk in the ROV EraYihao Chen, Qi Li, Ke Xu, Zhuotao Liu 等NDSS 2026
它引用的顶会 Paper6
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira 等NDSS 2017 · 被引用 108 次
- Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP RoutingJared M. Smith, Max SchuchardS&P 2018 · 被引用 71 次
- SICO: Surgical Interception Attacks by Manipulating BGP CommunitiesHenry Birge-Lee, Liang Wang, Jennifer Rexford, Prateek MittalCCS 2019 · 被引用 51 次
- On the Feasibility of Rerouting-Based DDoS DefensesMuoi Tran, Min Suk Kang, Hsu-Chun Hsiao, Wei-Hsuan Chiang 等S&P 2019 · 被引用 39 次
- Withdrawing the BGP Re-Routing Curtain: Understanding the Security Impact of BGP Poisoning through Real-World MeasurementsJared M. Smith, Kyle Birkeland, Tyler McDaniel, Max SchuchardNDSS 2020
相关 Paper
- BGP-iSec: Improved Security of Internet Routing Against Post-ROV AttacksCameron Morris, Amir Herzberg, Bing Wang, Samuel SecondoNDSS 2024
- Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the InternetTomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael WaidnerUSENIX Security 2023
- DISCO: Sidestepping RPKI's Deployment BarriersTomas Hlavacek, Ítalo Cunha, Yossi Gilad, Amir Herzberg 等NDSS 2020
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
