The Threat Landscape of IP Leasing in the RPKI Era
Weitong Li, Yongzhe Xu, Taejoong Chung
摘要
Short-term IPv4 leasing is on the rise, allowing address owners (lessors) to rent out spare address blocks to lessees who rely on them for critical operations. Yet under existing RPKI practices, the lessor remains the recognized authority, retaining full control over the ROAs needed to validate BGP announcements.
This paper uncovers how such arrangements fundamentally clash with the assumptions of route origin validation: even after leasing out an address block, the lessor can unilaterally invalidate the lessee's announcements, causing RPKI-enforcing ASes to drop or redirect traffic. We show that a malicious lessor can leverage RPKI to covertly hijack a leased prefix by feeding "lease-compliant" ROAs to select relying parties while presenting "rogue" ROAs to the rest of the Internet.
Through experiments on two major cloud platforms and the PEERING testbed, spanning multiple continents, we confirm that these attacks can reroute leased-prefix traffic with little visibility to the lessee or standard monitoring tools. We further illustrate scenarios in which a rogue lessor intercepts TLS certificate validation or executes region-specific hijacks, highlighting the severity of such threats. Finally, we propose practical mitigations, including multi-RP ROA verification, delegating ROA authority to neutral brokers, and adopting partial delegation in RIR portals.
By exposing the interplay between IP leasing and RPKI, we aim to spur both policy reforms and technical advancements that strengthen routing security in the face of ever-growing address shortages.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper6
- SICO: Surgical Interception Attacks by Manipulating BGP CommunitiesHenry Birge-Lee, Liang Wang, Jennifer Rexford, Prateek MittalCCS 2019 · 被引用 51 次
- Experiences Deploying Multi-Vantage-Point Domain Validation at Let's EncryptHenry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker 等USENIX Security 2021 · 被引用 23 次
- Beyond Limits: How to Disable Validators in Secure NetworksTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann 等SIGCOMM 2023 · 被引用 14 次
- Behind the Scenes of RPKITomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann 等CCS 2022 · 被引用 14 次
- Byzantine-Secure Relying Party for Resilient RPKIJens Frieß, Donika Mirdita, Haya Schulmann, Michael WaidnerCCS 2024 · 被引用 1 次
相关 Paper
- Demystifying RPKI-Invalid Prefixes: Hidden Causes and Security RisksWeitong Li, Tao Wan, Tijay ChungNDSS 2026
- Stalloris: RPKI Downgrade AttackTomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann 等USENIX Security 2022
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira 等NDSS 2017 · 被引用 108 次
- Crack in the Armor: Underlying Infrastructure Threats to RPKI Publication Point ReachabilityYunhao Liu, Jessie Hui Wang, Yuedong Xu, Zongpeng Li 等NDSS 2026
- Securing BGP ASAP: ASPA and other Post-ROV DefensesJustin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya 等NDSS 2025
