Securing BGP ASAP: ASPA and other Post-ROV Defenses
Justin Furuness, Cameron Morris, Reynaldo Morillo, Arvind Kasiliya, Bing Wang, Amir Herzberg
摘要
—Before the adoption of Route Origin Validation (ROV), prefix and subprefix hijacks were the most effective and common attacks on BGP routing. Recent works show that ROV adoption is increasing rapidly; with sufficient ROV adoption, prefix and subprefix attacks become ineffective. We study this changing landscape and in particular the Autonomous System Provider Authorization (ASPA) proposal, which focuses on route leakage but also foils some other attacks. Using recent measurements of real-world ROV adoption, we evaluate its security impact. Our simulations show substantial impact: already today , prefix hijacks are less effective than forged-origin hijacks, and the effectiveness of subprefix hijacks is much reduced. Therefore, we expect attackers to move to forged-origin hijacks and other post-ROV attacks ; we present a new, powerful post-ROV attack, first-ASN-stripping . We present extensive evaluations of different post-ROV defenses and attacks. Our results show that ASPA significantly protects against post-ROV attacks, even in partial adoption. It dramatically improves upon the use of only ROV or of BGPsec, Path-End, OTC, and EdgeFilter. BGP-iSec has even better protection but requires public-key operations to export/import announcements. We also present ASPAwN, an extension that further improves ASPA’s performance. Our results show that contrary to prior works [74], [95], ASPA is effective even when tier-1 ASes are not adopting, hence motivating ASPA adoption at edge and intermediate ASes. On the other hand, we find that against accidental route leaks, the simpler, standardized OTC mechanism is as effective as ASPA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- PathProb: Probabilistic Inference and Path Scoring for Enhanced and Flexible BGP Route Leak DetectionYingqian Hao, Hui Zou, Lu Zhou, Yuxuan Chen 等NDSS 2026 · 被引用 1 次
- ASRogue: Manipulating ASRank-Inferred AS RelationshipsYi Xu, Yihao Chen, Ke Xu, Qi Li 等USENIX Security 2026
- EZ-SAVE: Evaluation of Easy-to-Deploy Source Address Validation PoliciesNicholas Scaglione, Justin Furuness, Yossi Gilad, Hemi Leibowitz 等NSDI 2026
它引用的顶会 Paper4
- Are We There Yet? On RPKI's Deployment and SecurityYossi Gilad, Avichai Cohen, Amir Herzberg, Michael Schapira 等NDSS 2017 · 被引用 108 次
- ROV++: Improved Deployable Defense against BGP HijackingReynaldo Morillo, Justin Furuness, Cameron Morris, James Breslin 等NDSS 2021
- Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the InternetTomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael WaidnerUSENIX Security 2023
- DISCO: Sidestepping RPKI's Deployment BarriersTomas Hlavacek, Ítalo Cunha, Yossi Gilad, Amir Herzberg 等NDSS 2020
相关 Paper
- Understanding the Stealthy BGP Hijacking Risk in the ROV EraYihao Chen, Qi Li, Ke Xu, Zhuotao Liu 等NDSS 2026
- A System to Detect Forged-Origin BGP HijacksThomas Holterbach, Thomas Alfroy, Amreesh Phokeer, Alberto Dainotti 等NSDI 2024 · 被引用 21 次
- Understanding Route Origin Validation (ROV) Deployment in the Real World and Why MANRS Action 1 Is Not FollowedLancheng Qin, Li Chen, Dan Li, Honglin Ye 等NDSS 2024
- ImpROV: Measurement and Practical Mitigation of Collateral Damage in RPKI Route Origin ValidationWeitong Li, Yuze Li, Taejoong ChungUSENIX Security 2025
- iROV: Breaking the Silence of RPKI with Interactive ValidationYounsoo Kim, Seungjin Baek, Weitong Li, Tijay Chung 等USENIX Security 2026
