Although Internet routing security best practices have recently seen auspicious increases in uptake, ISPs have limited incentives to deploy them. They are operationally complex and expensive to implement, provide little competitive advantage, and protect only against origin hijacks, leaving unresolved the more general threat of path hijacks. We propose a new approach that achieves four design goals: improved incentive alignment to implement best practices; protection against path hijacks; expanded scope of such protection to customers of those engaged in the practices; and reliance on existing capabilities rather than needing complex new software in every participating router. Our proposal leverages an existing coherent core of interconnected ISPs to create a zone of trust, a topological region that protects not only all networks in the region, but all directly attached customers of those networks. Customers benefit from choosing ISPs committed to the practices, and ISPs thus benefit from committing to the practices. We compare our approach to other schemes, and discuss how a related proposal, ASPA, could be used to increase the scope of protection our scheme achieves. We hope this proposal inspires discussion of how the industry can make practical, measurable progress against the threat of route hijacks in the short term by leveraging institutionalized cooperation rooted in transparency and accountability.
翻译:尽管互联网路由安全最佳实践近期呈现出令人鼓舞的采用增长态势,但互联网服务提供商(ISP)部署这些实践的动机仍然有限。这些实践操作复杂且实施成本高昂,几乎不提供竞争优势,且仅能防范源劫持攻击,无法解决更具普遍性的路径劫持威胁。我们提出一种新方法,该方案实现四项设计目标:改进激励机制以促进最佳实践的实施;提供路径劫持防护;将此类防护范围扩展至实践参与者的客户;以及基于现有能力运行而非要求每个参与路由器安装复杂的新软件。我们的提案利用现有互联ISP形成的紧密核心,构建一个"信任区域"——该拓扑区域不仅保护区域内所有网络,还保护这些网络直接连接的客户。客户通过选择承诺采用最佳实践的ISP获益,而ISP则因践行这些实践获得回报。我们将所提方案与其他机制进行比较,并探讨如何通过相关提案ASPA扩大该方案的保护范围。我们希望此提案能激发业界讨论:如何依托植根于透明度与问责制的制度化合作,在短期内针对路由劫持威胁取得切实、可衡量的进展。