Toward the mutual routing security in wide area networks: A scoping review of current threats and countermeasures

Mikołaj Kowalski, Wojciech Mazurczyk · Computer Networks · 2023

The inter-domain routing security is often based on trust, which, as seen in practice, is an insufficient approach. Due to the deficit of native security controls in the Border Gateway Protocol (BGP), many new routing security measures were proposed to prevent control-plane abuse. They must be implemented in the majority of the Internet’s Autonomous Systems. This study undertakes a scoping review of the routing security domain to provide the most up-to-date and state-of-the-art broad summary of threat classification, prevention, and mitigation. The authors determine the progress of implementing countermeasures and explain the obstacles and research directions. This paper covers the current threat landscape and the existing taxonomies of attack vectors on the routing layer. By analyzing different taxonomies, we detected overlapping incident types. Therefore, a unified and consolidated taxonomy is proposed to preserve consistency among different attack types, simultaneously giving a more detailed breakdown of incident classification. This review also contains a comprehensive comparative study of protective measures, including historical, current, and developing techniques. This study includes the efficiency of proactive (prevention) and reactive (mitigation) practices and their caveats. The authors also examine the most promising development plans for new and existing countermeasures. Global implementation efforts are focused on routing security’s safeguard mechanisms based on mutual protection, e.g., the Resource Public Key Infrastructure (RPKI) system. This determinant creates an infinite regress problem known as the chicken or the egg—the primary dilemma. The authors find that the point of critical mass is achieved but that RPKI still faces vital issues.

Read the paper · More papers on PaperTik