Skip to main content

RPKI is coming of age: A longitudinal study of RPKI deployment and invalid route origins

Publication ,  Conference
Chung, T; Chandrasekaran, B; Maggs, BM; Aben, E; Choffnes, D; Mislove, A; Bruijnzeels, T; Levin, D; Van Rijswijk-Deij, R; Rula, J; Sullivan, N
Published in: Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC
October 21, 2019

Despite its critical role in Internet connectivity, the Border Gateway Protocol (BGP) remains highly vulnerable to attacks such as prefix hijacking, where an Autonomous System (AS) announces routes for IP space it does not control. To address this issue, the Resource Public Key Infrastructure (RPKI) was developed starting in 2008, with deployment beginning in 2011. This paper performs the first comprehensive, longitudinal study of the deployment, coverage, and quality of RPKI. We use a unique dataset containing all RPKI Route Origin Authorizations (ROAs) from the moment RPKI was first deployed, more than 8 years ago. We combine this dataset with BGP announcements from more than 3,300 BGP collectors worldwide. Our analysis shows the after a gradual start, RPKI has seen a rapid increase in adoption over the past two years. We also show that although misconfigurations were rampant when RPKI was first deployed (causing many announcements to appear as invalid) they are quite rare today. We develop a taxonomy of invalid RPKI announcements, then quantify their prevalence. We further identify suspicious announcements indicative of prefix hijacking and present case studies of likely hijacks. Overall, we conclude that while misconfigurations still do occur, RPKI is “ready for the big screen,” and routing security can be increased by dropping invalid announcements. To foster reproducibility and further studies, we release all RPKI data and the tools we used to analyze it into the public domain.

Duke Scholars

Altmetric Attention Stats
Dimensions Citation Stats

Published In

Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC

DOI

ISBN

9781450369480

Publication Date

October 21, 2019

Start / End Page

406 / 419
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Chung, T., Chandrasekaran, B., Maggs, B. M., Aben, E., Choffnes, D., Mislove, A., … Sullivan, N. (2019). RPKI is coming of age: A longitudinal study of RPKI deployment and invalid route origins. In Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC (pp. 406–419). https://doi.org/10.1145/3355369.3355596
Chung, T., B. Chandrasekaran, B. M. Maggs, E. Aben, D. Choffnes, A. Mislove, T. Bruijnzeels, et al. “RPKI is coming of age: A longitudinal study of RPKI deployment and invalid route origins.” In Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC, 406–19, 2019. https://doi.org/10.1145/3355369.3355596.
Chung T, Chandrasekaran B, Maggs BM, Aben E, Choffnes D, Mislove A, et al. RPKI is coming of age: A longitudinal study of RPKI deployment and invalid route origins. In: Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC. 2019. p. 406–19.
Chung, T., et al. “RPKI is coming of age: A longitudinal study of RPKI deployment and invalid route origins.” Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC, 2019, pp. 406–19. Scopus, doi:10.1145/3355369.3355596.
Chung T, Chandrasekaran B, Maggs BM, Aben E, Choffnes D, Mislove A, Bruijnzeels T, Levin D, Van Rijswijk-Deij R, Rula J, Sullivan N. RPKI is coming of age: A longitudinal study of RPKI deployment and invalid route origins. Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC. 2019. p. 406–419.

Published In

Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC

DOI

ISBN

9781450369480

Publication Date

October 21, 2019

Start / End Page

406 / 419