Assessing Network Infrastructure-as-Code Security using Open Source Software Analysis Techniques Applied to BGP/BIRD

Wahab Almuhtadi, Wynn Fenwick, Liam Henley-Vachon, Peter Mitchell · 2022

In this paper, the security quality of an open-source software application for IP networks called BIRD is examined. Free and open-source software applications are used in all areas of modern software development. BIRD handles the Border Gateway Protocol (BGP) sessions between many different Autonomous Systems (AS) and is a very popular routing engine used at Internet Exchange Points (IXP's) around the world. It is essential to perform an in-depth analysis when using open-source software to understand risks, develop or improve products to offset the risks of lenient source code acceptance criteria and easier exploit insertion. Testing consists of three different stages: Open Source Intelligence (OSINT) conducted on the contributors to determine intentions for involvement, Static Application Security Testing (SAST) carried out to examine the source code for potential bugs and security risks, and Dynamic Application Security Testing (DAST) dealing with verifying the stability of the program during run-time. Test results and analysis are in section IV.

Read the paper · More papers on PaperTik