IRRedicator: Pruning IRR with RPKI-Valid BGP Insights

Minhyeok Kang, Weitong Li, Roland van Rijswijk-Deij, Ted Taekyoung Kwon, Taejoong Chung · 2024

Border Gateway Protocol (BGP) provides a way of exchanging routing information to help routers construct their routing tables.However, due to the lack of security considerations, BGP has been suffering from vulnerabilities such as BGP hijacking attacks.To mitigate these issues, two data sources have been used, Internet Routing Registry (IRR) and Resource Public Key Infrastructure (RPKI), to provide reliable mappings between IP prefixes and their authorized Autonomous Systems (ASes).Each of the data sources, however, has its own limitations.IRR has been well-known for its stale Route objects with outdated AS information since network operators do not have enough incentives to keep them up to date, and RPKI has been slowly deployed due to its operational complexities.In this paper, we measure the prevalent inconsistencies between Route objects in IRR and ROA objects in RPKI.We next characterize inconsistent and consistent Route objects, respectively, by focusing on their BGP announcement patterns.Based on this insight, we develop a technique that identifies stale Route objects by leveraging a machine learning algorithm and evaluate its performance.From real trace-based experiments, we show that our technique can offer advantages against the status quo by reducing the percentage of potentially stale Route objects from 72% to 40% (of the whole IRR Route objects).In this way, we achieve 93% of the accuracy of validating BGP announcements while covering 87% of BGP announcements.To overcome the limitation, Resource Public Key Infrastructure (RPKI) was introduced in 2008; the main objective was to provide cryptographically verifiable attestation via a Route Origin Authorization (ROA) object, which can bind an IP prefix to the AS who is authorized to announce it.Thus, routers can validate BGP announcements by checking if the origin Autonomous System Number (ASN) announcing an IP prefix matches with the ASN in ROA.Despite its strong attestation, however, it has not been widely deployed yet due to the negative impact of misissued ROA, the certificate dependencies in the hierarchy of RPKI [27], [29], and its incapability of route-leak protection.Also, RPKI depends on the Public Key Infrastructure (PKI) managed by RIRs, the quality of RPKI deployment and its management is significantly different across the RIRs; for example, we found that on March 1st, 2023, 59.2% of IP prefixes in RIPE NCC, the European RIR, were covered by ROA objects, while only 23.9% of IP prefixes in AFRINIC, the RIR for Africa, were done ( §III), consistent with findings reported in 2019 [17].Because of this limitation, Mutually Agreed Norms for Routing Security (MANRS) recommends the use of both IRR and RPKI [60].Given the potential of IRR to complement the limitations of RPKI, several approaches have been suggested to enhance the quality of IRR objects.On one hand, certain Internet registries, such as the Japan Network Information Center (JP-NIC) managing JPIRR, have attempted to enforce rules within their IRR databases to address stale objects; for instance, JPIRR removes IRR objects that have not been updated for a specified timeframe [20], typically a year.However, this approach relies on active participation from network operators, who are required to re-register their objects annually.Unfortunately, the lack of sufficient incentives to adhere to this policy hinders its effectiveness.On the other hand, RIPE NCC, the Internet registry for Europe, utilizes RPKI to discard IRR objects that fail validation against RPKI.Furthermore, Internet

Read the paper · More papers on PaperTik