5 ms·
RPKI doesn't sign hops in the path for a BGP update. That means to hijack a prefix, all you need to do is to take a legitimate route and re-advertise it with yo
by pathseeker 6y ago
RPKI doesn't sign hops in the path for a BGP update. That means to hijack a prefix, all you need to do is to take a legitimate route and re-advertise it with your AS as the second hop in the path.
This isn't as damaging as being able to advertise a smaller prefix because it won't send all traffic to you. It will just send from routers where your path is shorter than the original.
To actually prevent hijacking via path shortening attacks like this, you need a full BGPSEC implementation https://en.wikipedia.org/wiki/BGPsec https://en.wikipedia.org/wiki/BGPsec which is a much higher barrier than RPKI because the crypto operations jump 1 or 2 orders of magnitude (signing every re-advertised route rather than just originated routes).
So RPKI gets the cert infra in place, but it doesn't really fully solve the problem.
- korethr 6y agoBut, with RPKI getting the cert infra in place, would that not then make it relatively easier to take that 2nd step, than when not even RPKI was in place?
- topranks 6y agoThe problem is the number of updates / changes that happen all the time in BGP, and having each router cryptographically validate each one / sign every update it sends.... it doesn’t scale well. The BGPSEC theory is there but not sure if we can make a workable system. https://www.potaroo.net/ispcol/2011-07/bgpsec.pdf https://www.potaroo.net/ispcol/2011-07/bgpsec.pdf
- mlyle 6y agoCurrent routers can't handle it, but ... it's not like routes changes that much that we're talking about an intolerable amount of RSA operations. We're really talking about fewer operations per day per router than some web frontends do in a second.
- tptacek 6y agoThat doesn't sound right? In 2018 there were, according to Geoff Huston, days with 700,000 updates per day. That sounds high for handshakes/second.
- mlyle 6y agoOK, OK, my bad; a single large multicore NGINX box can only do about 100k full TLS handshakes per second with 2048 RSA. So it'd be several seconds. On the other hand, verify is cheaper. My crappy laptop will do ~320k RSA-2048 verifications per second...
- deleted 6y ago[deleted]
- mititelu 6y agohttps://www.nginx.com/wp-content/uploads/2014/07/NGINX-SSL-P.. https://www.nginx.com/wp-content/uploads/2014/07/NGINX-SSL-P.... 350 per core per second... you are way off at 100k/s. If there is such a thing I'd really like to see setup to get it running / try it out myself as well. do note there are ways to cache ssl data so connections are resumed / avoid handshake again for same user
- mlyle 6y agohttps://www.nginx.com/blog/testing-performance-nginx-ingress-controller-kubernetes/ https://www.nginx.com/blog/testing-performance-nginx-ingress... 60k/second across 24 cores, admittedly on very fast hardware (though not using all the cores that hardware has). Pretty much the same number on 16 cores. In general, telling someone they're "way off" about performance and citing 6 year old benchmarks isn't a winning plan. In any case, it's immaterial to what we're discussing. My slow laptop could verify all the signatures for a busy day of updates in a couple seconds, and it's clearly -possible- to put a big fraction of this horsepower in a router.
- 6y ago
- londons_explore 6y agoA modern CPU can do how many thousands of signatures per second? How many internet routes change per second? How many dollars per second would pay for enough CPU's to sign every changed route? I'd bet less than one... I'd guess 1000x less than one...
- bifrost 6y agoRouters don't typically use PC cpus.
- job 6y agoFor the BGP portion of the work they absolutely do.
- bifrost 6y agoI'm not sure which platform you're talking about, mine uses PPC, which hasn't been in a desktop in quite some time. kern.version: JUNOS 18.XXX.X #0: XXXX-XX-XX 03:28:10 UTC builder@svl-junos-p001:/volume/build/junos/18.X/release/18.XXX.X/obj/powerpc/junos/bsd/kernels/JUNIPER-PPC/kernel There certainly are some routers that use x86 based CPUs, but they're embedded versions which you'd be unlikely to use on a PC.
- job 6y agoYou can easily do origin validation on that type of CPU. It’s a very efficient lookup.
- bifrost 6y agoI guess we'll see what happens TBH. I didn't realize it'd been available in JunOS since 12.2 which covers a variety of devices (even some old stuff I've seen on customer sites), I've yet to come across a site with it deployed. Maybe I should do some consulting for folks.
- 6y ago
- melanor9 6y agohttps://tools.ietf.org/html/draft-ietf-sidrops-aspa-profile-02 https://tools.ietf.org/html/draft-ietf-sidrops-aspa-profile-... https://tools.ietf.org/html/draft-ietf-sidrops-aspa-verification-04 https://tools.ietf.org/html/draft-ietf-sidrops-aspa-verifica...