3 ms·
For those of us unfamiliar with the term, can you explain RPKI and how it helps?
by Osiris 3y ago
For those of us unfamiliar with the term, can you explain RPKI and how it helps?
- sschueller 3y agoI didn't know either but I found this little snippet: Resource Public Key Infrastructure (RPKI) is a security framework by which network owners can validate and secure the critical route updates or Border Gateway Protocol (BGP) announcements between public Internet networks. BGP is essentially the central nervous system of the Internet and one of its fundamental building blocks. The main function of BGP is to facilitate efficient routing between Autonomous Systems (AS), by building and maintaining the Internet routing table. The Internet routing table is effectively the navigation system of the Internet and without it, traffic would be unable to flow between its constituent networks. Unfortunately, routing equipment alone cannot distinguish between legitimate and malicious routing announcements, but network operators who implement RPKI validation and filtering can choose to reject announcements from networks not authorized to advertise those resources. In other words, RPKI is essentially a secure identification system for the BGP route information between autonomous systems.
- chaz6 3y agoBefore RPKI, any network on the internet could announce any prefix (e.g. 2001:630::/32) to any neighbour, whether they had the right to or not. With RPKI, the owner of the prefix has to authorize a network to announce the route, so this helps to prevent networks from hijacking prefixes. One caveat is that it depends upon networks checking the RPKI database when receiving prefixes from neighbours, but pretty much all the major networks do this now. For more information, there is a good article here: https://phoenixnap.com/kb/rpki https://phoenixnap.com/kb/rpki
- icedchai 3y agoMore than 50% of prefixes still don't use RPKI. See https://rpki-monitor.antd.nist.gov/ https://rpki-monitor.antd.nist.gov/ Many will likely never use it. ARIN, for example, does not allow "legacy" networks to use RPKI unless they sign a registration agreement (and start paying for the privilege.)
- almost_usual 3y agoSimilar to CAs on the web in RPKI a TA (Trust Anchor) will sign a ROA (Route Origin Authorization X.509 certificate) to certify an ASN can originate routes within an address space. There are five TAs which are RIRs (Regional Internet Registries) AFRINIC, APNIC, ARIN, LACNIC, and RIPE. So similar to how your web browser can determine a website is valid or not by checking the certificate is signed by a CA. A network can determine a route is valid or not by checking the ROA is signed by a TA.
- salawat 3y agohttps://www.arin.net/resources/manage/rpki/ https://www.arin.net/resources/manage/rpki/ Basically, RPKI is to BGP as things like DKIM are to email, or DNSSEC is to the DNS system. Different AS's announce route prefix's to attract packets from other AS's. Orgs like ARIN and such act as trust anchors (CA's, in Web of Trust parlance) for Network operators who use RPKI clients to validate incoming BGP announcements cryptographically against the trust anchor list. The idea would be that an Iraqi telco could announce they terminate a prefix they don't, blackholing the traffic originating from within their network to those prefixes, but they wouldn't get the cryptographic vouch by their RIR, so other AS's would ignore altering their routing tables. Insulating the damage to essentially inside the network that was making the fraudulent announcement. It could even still be worked around by people internal to that network as long as they cross into another AS's routing domain, say by VPN, which would then allow traffic to route as normal. There is the argument to be made that RPKI is only as useful as the numbering authorities are capable of maintaining a strict position of neutrality. Thus is the way of all of all Trust. It is alas, the best we have.