Professional Documents
Culture Documents
Presentation Subtitle
4
e
Section Title
Section subtitle
Internet building blocks
ASN Addresses
ASN (Autonomous System Interconnect
Number)
7
Routing on the Internet
Can I Is A
trust B? correct?
“BGP protocol”
A B: “I have 194.x.x.x” B
193.x.x.x 194.x.x.x
A: “I have 193.x.x.x”
RPKI Webinar 8
Route Propagation
7 00
=
AS15 M
E D
40 AS756 AS164 AS33
LP=
MED=500
LP=100
R1 R2 66.2.9.0/24
route
LP
=5
0 tra c
AS25 AS5
9
ffi
Accidents Happen
• Fat Fingers
- 2 and 3 are really close on our keyboards….
RPKI Webinar 10
Incidents Are Common
• 2019 Routing Security Review
- 12,600 incidents
- 4,4% of all ASNs affected
- 3,000 ASNs are victims of at least one incident
- 1,300 ASNs caused at least one incident
Source: https://bgpstream.com
RPKI Webinar 11
Routing on the Internet
Can I Is A
trust B? correct?
A B: “I have 194.x.x.x” B
193.x.x.x 194.x.x.x
A: “I have 193.x.x.x”
RPKI Webinar 12
Problem Statement
• Some IRR data can not be fully trusted
- Accuracy
- Incomplete data
- Lack of maintenance
• 14
Section Title
Section subtitle
Resource Public Key Infrastructure
ALL Resources
public key
LIR’s Resources
public key
signature
Signing Validating
ALL Resources
public key
signature
ROA Prefix
is authorised to be announced by
signature AS Number
RIPE
ROA
Signing Validating
List of ROAs
Cerfificates
Cerfificates
Validator
BGP Announcements
AS111 10.0.8.0/22
ROA AS222 10.0.6.0/24
AS333 10.4.16.0/20
AS111 10.0.12.0/22
AS111 10.0.16.0/22
AS111 10.0.20.0/22
RPKI Repository
A is authorised
to announce 2. Validate route
192.0.2.0/24
Is A
1. Create route correct?
authorisation record
(ROA)
A B
BGP
192.0.2.0/24 193.0.24.0/21
A: “I have 192.0.2.0/24”
RPKI Webinar 31
Status of Transit and Cloud
Name Type Details Status
Telia Transit Signed & Filtering Safe
Cogent Transit Signed & Filtering Safe
GTT Transit Signed & Filtering Safe
NTT Transit Signed & Filtering Safe
Hurricane Electric Transit Signed & Filtering Safe
Tata Transit Signed & Filtering Safe
PCCW Transit Signed & Filtering Safe
RETN Transit Partially Signed & Safe
Cloud are Cloud Filtering
Signed & Filtering Safe
Amazon Cloud Signed & Filtering Safe
Net ix Cloud Signed & Filtering Safe
Wikimedia Cloud Signed & Filtering Safe
Foundation
Scaleway Cloud Signed & Filtering Safe
• Source: isbgpsafeyet.com 32
fl
fl
What We’re Working On
• Repository Resiliency: Cloud
• Security: Audit Framework, different security
assessments
• Improving Q&A
• Reporting on our findings
• Doing RPKI ourselves!