A Certificate Pin BGP Protocol: CP-BGP
Yanwei Wu, Ru Wang, Xiaohua Xu · 2020 5th International Conference on Computer and Communication Systems (ICCCS) · 2020
Border Gateway Protocol (BGP) is always the target of the attacks since it is the only routing protocol connecting different Autonomous Systems (ASes) in Internet. BGP fraud is one of the common attacks targeting BGP routing on Internet. YouTube hijacking in 2008 and recent Google traffic hijacking in 2018 are because of routing hijacking. There are existing secure protocols designed to prevent BGP fraud. But they either heavily rely on the Central Authorities (CAs) or need complicate calculations, and thus result in inefficient implementation. We design a Certificate Pin BGP (CP-BGP) protocol to moves majority CA related communications and calculations offline and reduce the dependency of CAs. We analyze real-time BGP traffic data collected by Route Views Project of University of Oregon [1] to prove the performance of CP-BGP and show the proposed protocol, CP-BGP, provides routing hijacking prevention and prefix fraud prevention without decreasing much performance.