Exploiting vulnerabilities at IXP route servers to perform stealth BGP hijacks
Gabby Rimlinger, Joaquim Pereira, Matthieu Gouel, Olivier Fourmaux, Timur Friedman, Pedro Marcos, Cristel Pelsser, Ronaldo A. Ferreira, Kevin Vermeulen
摘要
Internet Exchange Points (IXPs) are critical Internet infrastructure that interconnect tens of thousands of Autonomous Systems (ASes). To support scalable multilateral route exchange and fine-grained routing control, IXPs provide services such as route servers for scalable route dissemination and BGP communities for selective advertisement. Route servers enable both scalability and expressive routing policies, but some of their design choices can be exploited by a malicious actor. In this paper, we identify two of them: route-server path-hiding mitigation and the deployment of multiple independent route servers. Combined with well-known hijack techniques, these design choices allow an attacker to make multiple routes to the same prefix co-exist at the IXP, and strategically disseminate malicious routes to different subsets of peers, to increase their attack surface and the number of potentially vulnerable prefixes. We validate the feasibility of our attacks across three large IXPs, and show that these attacks increase the number of polluted ASes by 28% to 366%, and the number of vulnerable prefixes by 41% to 61%, depending on the IXP, compared to prior work. Moreover, we show that the IXP environment makes it easier to perform interception attacks than in other settings and allows such attacks to be invisible to public BGP collector peers. We also propose a novel data-plane detection technique based on the Layer-2 IXP architecture. Finally, drawing on discussions with IXP operators, we provide practical recommendations to improve route security and visibility at IXPs.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the InternetTomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael WaidnerUSENIX Security 2023
- Crack in the Armor: Underlying Infrastructure Threats to RPKI Publication Point ReachabilityYunhao Liu, Jessie Hui Wang, Yuedong Xu, Zongpeng Li 等NDSS 2026
- Stalloris: RPKI Downgrade AttackTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann 等USENIX Security 2022
- LARS: Keeping Local Traffic Local with Latency-Aware Route Servers at IXPsDavid De Andres Hernandez, Yasin Alhamwy, Daniel Wagner, Maximilian Stephan 等SIGCOMM 2026 · 被引用 1 次
- United We Stand: Collaborative Detection and Mitigation of Amplification DDoS Attacks at ScaleDaniel Wagner, Daniel Kopp, Matthias Wichtlhuber, Christoph Dietzel 等CCS 2021 · 被引用 50 次
