News: 1585656006

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Watch your MANRS: Akamai, Amazon, Netflix, Microsoft, Google, and pals join internet routing security effort

(2020/03/31)


An internet community effort to improve routing security has got a boost from some of the internet’s biggest names.

Amazon, Google, Facebook, Microsoft, Akamai, and Netflix, among others, have signed up to the Mutually Agreed Norms for Routing Security ( [1]MANRS ) group, in their roles as content delivery networks (CDNs) and cloud providers (CPs).

MANRS’s goal is to shore up the internet's lax security when it comes to routing people's connections around Earth. It is, essentially, depending on the circumstances, too easy for miscreants to hijack and redirect internet traffic from legit servers to malicious machines so that web browsing and other online activities can be snooped on or meddled with.

This widespread issue is something that has become [2]increasingly important in the past few years as the number and size of connectivity breakdowns and attacks on the global system have grown. Criminals and [3]possibly government spies have realized the potential that exists in snatching people's internet traffic for surveillance, disruption, and theft.

The MANRS group pushes four main approaches, two technical and two cultural: filtering, anti-spoofing, and then coordination and validation. Combined, they help weed out bad routing information and so reduce the ability to carry out attacks.

Akamai, Azion, and Cloudflare have also signed up to MANRS, bringing membership up to over 300 organizations and covering a significant chunk of global internet traffic (roughly 50 per cent in fact).

Several of those organizations provided canned quotes explaining why they’d joined. “Being MANRS compliant not only improves our routing security capabilities, but has the potential to help other networks to improve theirs,” said Akamai’s VP of network technology Christian Kaufmann.

Cloudflare CTO John Graham-Cumming said: “Route leaks have a cascading negative impact on businesses, and coordinated action is needed by the Internet infrastructure community to improve the security, resilience, and reliability of networks.”

Netflix Open Connect’s VP Gina Haspilaire said: “A secure routing framework is essential to maintaining the ongoing health and stability of the global Internet, and MANRS provides the resources to develop, foster, and promote this framework.”

Awareness

Those companies interconnect with thousands of other networks, and so the hope is that signing up these giants to MANRS will lead to concrete action among the roughly 60,000 network operators that make up the global internet – and that routing security will be taken more seriously.

Mind your MANRS: Internet Society names and shames network operators that bungle their routing security [4]READ MORE

We spoke to the Internet Society’s Technology Program Manager, Andrei Robachevsky, who oversees many of the efforts. He is hopeful that it will lead to a significant reduction in the number of route hijackings, blunders, and misconfigurations.

“We hope this will build peer pressure inside the community,” he noted, pointing to a decrease in incidents in each of the three years that MANRS has been running and expanding. “This will increase scalability and provide more transparency.”

MANRS has its own [5]metrics engine called the MANRS Observatory which Robachevsky says had added new features, although most of them are not public. Only members can see behind the curtain where those network operators that are causing most of the problems are visible.

When asked if MANRS will name-and-shame the worst, he said “not yet,” and argued that it was too early for such trend analysis. The truth is that the industry hopes good old-fashioned peer pressure will resolve most of the issues.

Checking

Despite occasional claims of state-level hacking efforts, most routing problems are more a result of bad configuration settings and lax security controls by operators.

“It is always going to be an arms race,” he told The Register . It’s also not a matter of fixing your systems once and being done. “You have to create a process,” Robachevsky notes. “And have a security framework that creates ongoing checks on compliance.”

Every new member that joins MANRS is given an audit check, though Robachevsky says that may need to be expanded to occasional spot-checks to ensure that organizations remain compliant with [6]the group's standards .

In a clear sign that the approach may be working the way intended, we asked about one network operator that has been [7]repeatedly fingered as a source of problematic routing: China Telecom. We asked if MANRS had spoken to the outfit, and Robachevsky told us the opposite had happened.

“In fact, they reached out to us,” he said, noting that it seemed genuinely interested in working with MANRS to fix its issues.

There is nothing to oblige any network operator, exchange point, CDN or CP to sign up with MANRS, and in that respect the entire process is dependent on MANRS’ standing and reputation. Today’s announcement will help bolster both. ®



[1] https://www.manrs.org/about/

[2] https://www.theregister.co.uk/2019/06/24/verizon_bgp_misconfiguration_cloudflare/

[3] https://www.theregister.co.uk/2018/08/01/bgp_route_leak_telegram_iran/

[4] https://www.theregister.co.uk/2019/08/14/internet_society_manrs_stats/

[5] https://www.theregister.co.uk/2019/08/14/internet_society_manrs_stats/

[6] https://www.manrs.org/resources/

[7] https://www.theregister.co.uk/2019/06/10/bgp_route_hijack_china_telecom/

Unlimiting Progress in Leaps and Bounds

amanfromMars 1

This widespread issue is something that has become increasingly important in the past few years as the number and size of connectivity breakdowns and attacks on the global system have grown.

When that widespread issue is an Intelligently Designed Default Facility and Virtually Remote Advancing ACTive IT Utility, are any and all attacks upon and against it always extraordinarily rendered self-destructive and counter-productive.

Take extreme care when daring to venture and engage with forces and sources drivering events over horizons and through stumbling blocks there.

Be better than just good is more than just excellent sound advice to survive practically intact and fully loded for as long as ever IT is dealt there.

“In fact, they [China Telecom] reached out to us,” he said, noting that it seemed genuinely interested in working with MANRS to fix its issues.

Bravo, China Telecom. ..... deciding on one of the SMARTR Ways To Go .... Jumping into the Deep and Dark Ends with Wannabe Sharks and Almighty Whales.

I see what you did there!

Jamie Jones

"The truth is that the industry hopes good old-fashioned peer pressure will resolve most of the issues."

"...web browsing and other online activities can be snooped on..."

Error 418

It's good to know companies like Google, Facebook and Microsoft are so concerned about people's internet activities being snooped on.

Re: "...web browsing and other online activities can be snooped on..."

IGotOut

You misunderstood. The WRONG people are snooping, you know governments. So long as it's private enterprise making money from it, there is no problem.

Don't like it? Then clearly you are a left wig, socialist loving , red commie traitor!

Doctor Syntax

To what extent would this be proof of government bad actors? Logging requirements, national security letters and the like must make all of the participants liable to interference.

Relations are simply a tedious pack of people, who haven't the remotest
knowledge of how to live, nor the smallest instinct about when to die.
-- Oscar Wilde, "The Importance of Being Earnest"