Cross-posting for potential interest.

Date: Tuesday, November 10, 2015 at 8:12 PM
Just a reminder for tomorrow's BUsec seminar. Avichai Cohen from Hebrew University of Jerusalem will talk about Jumpstarting Interdomain Routing Security.

Title: Jumpstarting Interdomain Routing Security
Speaker: Avichai Cohen, Hebrew University of Jerusalem
Wednesday Nov. 11, 10-11am


Extensive standardization and R&D efforts are dedicated to establishing secure interdomain routing. These efforts focus on two complementary mechanisms: origin authentication with RPKI, and path validation with BGPsec. However, while RPKI is finally gaining traction, the adoption of BGPsec seems not even on the horizon. This is due to inherent, possibly insurmountable, obstacles, including the need to replace today's routing infrastructure, meagre benefits in partial deployment, and the overhead of online cryptography. We aim to design lightweight alternatives to BGPsec that can significantly improve interdomain routing security.

We propose path-end validation, a modest extension to RPKI that does not require modifications to BGP message format nor online cryptography. We show, through extensive simulations on empirically-derived datasets, that path-end validation yields significant security benefits, even with very limited partial deployment. We present an open-source prototype implementation of path-end validation, which does not require changing today's routers, illustrating the deployability advantage over BGPsec. We also explore additional mechanisms for jumpstarting interdomain routing security.

Joint work with Yossi Gilad (Hebrew University), Amir Herzberg (Bar-Ilan University) and Michael Schapira (Hebrew University)

