Protecting the integrity of internet routing:
William Haag, Doug Montgomery, William C. Barker, Allen Tan · 2019
▪ It is difficult to overstate the importance of the internet to modern business and to society in general.The internet is essential to the exchange of all manner of information, including transactional data, marketing and advertising information, remote access to services, entertainment, and much more.▪ The internet is not a single network, but rather a complex grid of independent interconnected networks.The design of the internet is based on a trust relationship between these networks and relies on a protocol known as the Border Gateway Protocol (BGP) to route traffic among the various networks worldwide.BGP is the protocol that internet service providers (ISPs) and enterprises use to exchange route information between them.▪ Unfortunately, BGP was not designed with security in mind.Traffic typically traverses multiple networks to get from its source to its destination.Networks implicitly trust the BGP information that they receive from each other, making BGP vulnerable to route hijacks.▪ A route hijack attack can deny access to internet services, misdeliver traffic to malicious endpoints, and cause routing instability.A technique known as BGP route origin validation (ROV) is designed to protect against route hijacking.▪ The National Cybersecurity Center of Excellence (NCCoE) at the National Institute of Standards and Technology (NIST) has developed proof-of-concept demonstrations of a BGP ROV implementation designed to improve the security of the internet's routing infrastructure.▪ This NIST Cybersecurity Practice Guide demonstrates how networks can protect BGP routes from vulnerability to route hijacks by using available security protocols, products, and tools to perform BGP ROV to reduce route hijacking threats.The example implementation described in this guide aims to protect the integrity and improve the resiliency of internet traffic exchange by verifying the source of the route. CHALLENGEMost of the routing infrastructure underpinning the internet currently lacks basic security services.In most cases, internet traffic must transit multiple networks before reaching its destination.Each network implicitly trusts other networks to provide (via BGP) the accurate information necessary to correctly route traffic across the internet.When that information is inaccurate, traffic will take inefficient paths through the internet, arrive at malicious sites that masquerade as legitimate destinations, or never arrive at its intended destination.These impacts can be mitigated through a widespread adoption of BGP ROV.To date, ISPs and enterprises have been slow to adopt BGP ROV for reasons that include an unavailability of detailed BGP ROV deployment, operation, and management guidelines, as well as lingering concerns and questions about functionality, performance, availability, scalability, and policy implications.These concerns need to be addressed so that potential users of BGP ROV can appreciate the feasibility of using BGP ROV and the increased security that it can provide.NIST SP 1800-14B: Protecting the Integrity of Internet Routing i DISCLAIMER Certain commercial entities, equipment, products, or materials may be identified by name or company logo or other insignia in order to acknowledge their participation in this collaboration or to describe an experimental procedure or concept adequately.Such identification is not intended to imply special status or relationship with NIST or recommendation or endorsement by NIST or NCCoE; neither is it intended to imply that the entities, equipment, products, or materials are necessarily the best available for the purpose.