5. Combating prefix hijacking
As seen in the previous paragraphs, it is impossible for a network administrator to maintain a list of associations between AS numbers and the prefixes they are authorized to issue. As a result, the risk of prefix usurpation is very high. Global monitoring tools frequently record occurrences of this type of incident, and are essential for detecting them and triggering appropriate reactions . To combat this vulnerability and improve routing security on the Internet, the RPKI (Resource Public Key Infrastructure, ) architecture was devised. The aim is to cryptographically validate that a given autonomous system is authorized to originate routes to a given...
Exclusive to subscribers. 97% yet to be discovered!
You do not have access to this resource.
Click here to request your free trial access!
Already subscribed? Log in!
The Ultimate Scientific and Technical Reference
This article is included in
Networks and Telecommunications
This offer includes:
Knowledge Base
Updated and enriched with articles validated by our scientific committees
Services
A set of exclusive tools to complement the resources
Practical Path
Operational and didactic, to guarantee the acquisition of transversal skills
Doc & Quiz
Interactive articles with quizzes, for constructive reading
Combating prefix hijacking
Bibliography
Websites
ANSSI (Agence nationale de la sécurité des systèmes d'information). – "Recommendations and guides" portal: BGP configuration best practice guide. http://www.ssi.gouv.fr/fr/guides-et-bonnes-pratiques/recommandations-et-guides/securite-des-reseaux/le-guide-des-bonnes-pratiques-de-configuration-de-bgp.html
...Standards and norms
- A border gateway protocol 4 (BGP-4), IETF request for comments - RFC 4271 - 2006
- Transmission control protocol, IETF request for comments. - RFC 793 - 1981
- BGP support for four-octet AS number space, IETF request for comments - RFC 4893 - 2007
- Stealing the internet, an internet-scale man in the middle attack, Defcon 16 http://www.defcon.org/images/defcon-16/dc16-presentations/defcon-16-pilosov-kapela.pdf...
Directory
Organizations – Federations – Associations (non-exhaustive list)
Center for Applied Internet Data Analysis (CAIDA) is a collaborative initiative between commercial, governmental and research entities to promote cooperation in the design of network infrastructures and the maintenance of a robust global Internet. http://www.caida.org/home/
...Exclusive to subscribers. 97% yet to be discovered!
You do not have access to this resource.
Click here to request your free trial access!
Already subscribed? Log in!
The Ultimate Scientific and Technical Reference