ROV++: Improved Deployable Defense against BGP Hijacking
Reynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin, Amir Herzberg, Bing Wang
摘要
—We study and extend Route Origin Validation (ROV), the basis for the IETF defenses of interdomain routing. We focus on two important hijack attacks: subprefix hijacks and non-routed prefix hijacks . For both attacks, we show that, with partial deployment, ROV provides disappointing security benefits. We also present a new attack, superprefix hijacks , which completely circumvent ROV’s defense for non-routed prefix hijacks. We then present ROV++, a novel extension of ROV, with significantly improved security benefits even with partial adoption. For example, with uniform 5% adoption for edge ASes (ASes with no customers or peers), ROV prevents less than 5% of subprefix hijacks, while ROV++ prevents more than 90% of subprefix hijacks. ROV++ also defends well against non-routed prefix attacks and the novel superprefix attacks. We evaluated several ROV++ variants, all sharing the improvements in defense; this includes “Lite”, software-only variants, deployable with existing routers. Our evaluation is based on extensive simulations over the Internet topology. We also expose an obscure yet important aspect of BGP, much amplified by ROV: inconsistencies between the observable BGP path (control-plane) and the actual traffic flows (data-plane). These inconsistencies are highly relevant for security, and often lead to a challenge we refer to as hidden hijacks
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- From Address Blocks to Authorized Prefixes: Redesigning RPKI ROV with a Hierarchical Hashing Scheme for Fast and Memory-Efficient ValidationZedong Ni, Yinbo Xu, Hui Zou, Yanbiao Li 等NSDI 2025 · 被引用 3 次
- Byzantine-Secure Relying Party for Resilient RPKIJens Frieß, Donika Mirdita, Haya Schulmann, Michael WaidnerCCS 2024 · 被引用 1 次
- Pruning the Tree: Rethinking RPKI Architecture from the Ground upHaya Schulmann, Niklas VogelNDSS 2026 · 被引用 1 次
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
- POPS: From History to Mitigation of DNS Cache Poisoning AttacksYehuda Afek, Harel Berger, Anat Bremler-BarrUSENIX Security 2025
它引用的顶会 Paper2
相关 Paper
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya 等NDSS 2025
- Understanding the Stealthy BGP Hijacking Risk in the ROV EraYihao Chen, Qi Li, Ke Xu, Zhuotao Liu 等NDSS 2026
- iROV: Breaking the Silence of RPKI with Interactive ValidationYounsoo Kim, Seungjin Baek, Weitong Li, Tijay Chung 等USENIX Security 2026
- ImpROV: Measurement and Practical Mitigation of Collateral Damage in RPKI Route Origin ValidationWeitong Li, Yuze Li, Taejoong ChungUSENIX Security 2025
- Understanding Route Origin Validation (ROV) Deployment in the Real World and Why MANRS Action 1 Is Not FollowedLancheng Qin, Li Chen, Dan Li, Honglin Ye 等NDSS 2024
