Towards Data-Driven Internet Routing Security
The Internet infrastructure is critical for the security and reliability of online daily life. The Border Gateway Protocol (BGP), the defacto global routing protocol, was not designed to cope with untrustworthy parties, making BGP vulnerable to misconfigurations and attacks from anywhere in the netw...
Main Author: | |
---|---|
Other Authors: | |
Format: | Thesis |
Published: |
Massachusetts Institute of Technology
2022
|
Online Access: | https://hdl.handle.net/1721.1/139960 |
_version_ | 1811085514901553152 |
---|---|
author | Testart Pacheco, Cecilia Andrea |
author2 | Clark, David D. |
author_facet | Clark, David D. Testart Pacheco, Cecilia Andrea |
author_sort | Testart Pacheco, Cecilia Andrea |
collection | MIT |
description | The Internet infrastructure is critical for the security and reliability of online daily life. The Border Gateway Protocol (BGP), the defacto global routing protocol, was not designed to cope with untrustworthy parties, making BGP vulnerable to misconfigurations and attacks from anywhere in the network. Recently, unintended large-scale misconfigurations caused significant amount of Internet traffic towards major providers to be dropped for hours, and through BGP attacks, perpetrators have stolen millions in fraudulent transactions. Nonetheless, little has changed in operational environments despite the many proposals to increase security by the research, standardization and industry communities. The problem space is complex: it involves multiple stakeholders, with different interests and available resources, and increasingly, geopolitical challenges. Yet, these stakeholders ultimately need to cooperate and coordinate their efforts to improve security. This dissertation proposes a holistic approach to study routing security. It includes the assessment of barriers of adoption of technical proposals to secure BGP, the empirical analysis of exploitations and misconfiguration due to BGP design flaws, as well as the empirical study of the mitigation strategies deployment and benefits. This analysis reveals the extent of misbehavior and misconfiguration in the use of BGP, and the benefit that operational security practices provide. It also discusses this new evidence in the context of tradeoff that have prevented the adoption of routing security. Finally, it provides a set of actions, which could be orchestrated by a bottom-up industry effort or top-down by governments, and directions for future technical work that would encourage collective adoption of security in BGP. |
first_indexed | 2024-09-23T13:10:48Z |
format | Thesis |
id | mit-1721.1/139960 |
institution | Massachusetts Institute of Technology |
last_indexed | 2024-09-23T13:10:48Z |
publishDate | 2022 |
publisher | Massachusetts Institute of Technology |
record_format | dspace |
spelling | mit-1721.1/1399602022-02-08T03:32:31Z Towards Data-Driven Internet Routing Security Testart Pacheco, Cecilia Andrea Clark, David D. Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science The Internet infrastructure is critical for the security and reliability of online daily life. The Border Gateway Protocol (BGP), the defacto global routing protocol, was not designed to cope with untrustworthy parties, making BGP vulnerable to misconfigurations and attacks from anywhere in the network. Recently, unintended large-scale misconfigurations caused significant amount of Internet traffic towards major providers to be dropped for hours, and through BGP attacks, perpetrators have stolen millions in fraudulent transactions. Nonetheless, little has changed in operational environments despite the many proposals to increase security by the research, standardization and industry communities. The problem space is complex: it involves multiple stakeholders, with different interests and available resources, and increasingly, geopolitical challenges. Yet, these stakeholders ultimately need to cooperate and coordinate their efforts to improve security. This dissertation proposes a holistic approach to study routing security. It includes the assessment of barriers of adoption of technical proposals to secure BGP, the empirical analysis of exploitations and misconfiguration due to BGP design flaws, as well as the empirical study of the mitigation strategies deployment and benefits. This analysis reveals the extent of misbehavior and misconfiguration in the use of BGP, and the benefit that operational security practices provide. It also discusses this new evidence in the context of tradeoff that have prevented the adoption of routing security. Finally, it provides a set of actions, which could be orchestrated by a bottom-up industry effort or top-down by governments, and directions for future technical work that would encourage collective adoption of security in BGP. Ph.D. 2022-02-07T15:15:49Z 2022-02-07T15:15:49Z 2021-09 2021-09-21T19:29:53.020Z Thesis https://hdl.handle.net/1721.1/139960 In Copyright - Educational Use Permitted Copyright MIT http://rightsstatements.org/page/InC-EDU/1.0/ application/pdf Massachusetts Institute of Technology |
spellingShingle | Testart Pacheco, Cecilia Andrea Towards Data-Driven Internet Routing Security |
title | Towards Data-Driven Internet Routing Security |
title_full | Towards Data-Driven Internet Routing Security |
title_fullStr | Towards Data-Driven Internet Routing Security |
title_full_unstemmed | Towards Data-Driven Internet Routing Security |
title_short | Towards Data-Driven Internet Routing Security |
title_sort | towards data driven internet routing security |
url | https://hdl.handle.net/1721.1/139960 |
work_keys_str_mv | AT testartpachecoceciliaandrea towardsdatadriveninternetroutingsecurity |