Towards Data-Driven Internet Routing Security

The Internet infrastructure is critical for the security and reliability of online daily life. The Border Gateway Protocol (BGP), the defacto global routing protocol, was not designed to cope with untrustworthy parties, making BGP vulnerable to misconfigurations and attacks from anywhere in the netw...

Full description

Bibliographic Details
Main Author: Testart Pacheco, Cecilia Andrea
Other Authors: Clark, David D.
Format: Thesis
Published: Massachusetts Institute of Technology 2022
Online Access:https://hdl.handle.net/1721.1/139960
_version_ 1811085514901553152
author Testart Pacheco, Cecilia Andrea
author2 Clark, David D.
author_facet Clark, David D.
Testart Pacheco, Cecilia Andrea
author_sort Testart Pacheco, Cecilia Andrea
collection MIT
description The Internet infrastructure is critical for the security and reliability of online daily life. The Border Gateway Protocol (BGP), the defacto global routing protocol, was not designed to cope with untrustworthy parties, making BGP vulnerable to misconfigurations and attacks from anywhere in the network. Recently, unintended large-scale misconfigurations caused significant amount of Internet traffic towards major providers to be dropped for hours, and through BGP attacks, perpetrators have stolen millions in fraudulent transactions. Nonetheless, little has changed in operational environments despite the many proposals to increase security by the research, standardization and industry communities. The problem space is complex: it involves multiple stakeholders, with different interests and available resources, and increasingly, geopolitical challenges. Yet, these stakeholders ultimately need to cooperate and coordinate their efforts to improve security. This dissertation proposes a holistic approach to study routing security. It includes the assessment of barriers of adoption of technical proposals to secure BGP, the empirical analysis of exploitations and misconfiguration due to BGP design flaws, as well as the empirical study of the mitigation strategies deployment and benefits. This analysis reveals the extent of misbehavior and misconfiguration in the use of BGP, and the benefit that operational security practices provide. It also discusses this new evidence in the context of tradeoff that have prevented the adoption of routing security. Finally, it provides a set of actions, which could be orchestrated by a bottom-up industry effort or top-down by governments, and directions for future technical work that would encourage collective adoption of security in BGP.
first_indexed 2024-09-23T13:10:48Z
format Thesis
id mit-1721.1/139960
institution Massachusetts Institute of Technology
last_indexed 2024-09-23T13:10:48Z
publishDate 2022
publisher Massachusetts Institute of Technology
record_format dspace
spelling mit-1721.1/1399602022-02-08T03:32:31Z Towards Data-Driven Internet Routing Security Testart Pacheco, Cecilia Andrea Clark, David D. Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science The Internet infrastructure is critical for the security and reliability of online daily life. The Border Gateway Protocol (BGP), the defacto global routing protocol, was not designed to cope with untrustworthy parties, making BGP vulnerable to misconfigurations and attacks from anywhere in the network. Recently, unintended large-scale misconfigurations caused significant amount of Internet traffic towards major providers to be dropped for hours, and through BGP attacks, perpetrators have stolen millions in fraudulent transactions. Nonetheless, little has changed in operational environments despite the many proposals to increase security by the research, standardization and industry communities. The problem space is complex: it involves multiple stakeholders, with different interests and available resources, and increasingly, geopolitical challenges. Yet, these stakeholders ultimately need to cooperate and coordinate their efforts to improve security. This dissertation proposes a holistic approach to study routing security. It includes the assessment of barriers of adoption of technical proposals to secure BGP, the empirical analysis of exploitations and misconfiguration due to BGP design flaws, as well as the empirical study of the mitigation strategies deployment and benefits. This analysis reveals the extent of misbehavior and misconfiguration in the use of BGP, and the benefit that operational security practices provide. It also discusses this new evidence in the context of tradeoff that have prevented the adoption of routing security. Finally, it provides a set of actions, which could be orchestrated by a bottom-up industry effort or top-down by governments, and directions for future technical work that would encourage collective adoption of security in BGP. Ph.D. 2022-02-07T15:15:49Z 2022-02-07T15:15:49Z 2021-09 2021-09-21T19:29:53.020Z Thesis https://hdl.handle.net/1721.1/139960 In Copyright - Educational Use Permitted Copyright MIT http://rightsstatements.org/page/InC-EDU/1.0/ application/pdf Massachusetts Institute of Technology
spellingShingle Testart Pacheco, Cecilia Andrea
Towards Data-Driven Internet Routing Security
title Towards Data-Driven Internet Routing Security
title_full Towards Data-Driven Internet Routing Security
title_fullStr Towards Data-Driven Internet Routing Security
title_full_unstemmed Towards Data-Driven Internet Routing Security
title_short Towards Data-Driven Internet Routing Security
title_sort towards data driven internet routing security
url https://hdl.handle.net/1721.1/139960
work_keys_str_mv AT testartpachecoceciliaandrea towardsdatadriveninternetroutingsecurity