News: 1665343868

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

That thing to help protect internet traffic from hijacking? It's broken

(2022/10/09)


An internet security mechanism called Resource Public Key Infrastructure (RPKI), intended to safeguard the routing of data traffic, is broken, according to security experts from Germany's ATHENE, the National Research Center for Applied Cybersecurity.

That means if you were hoping RPKI would prevent state spies and rogue operators from redirecting people's connections to snoop on them or break their connectivity, you may be disappointed: it can be circumvented, we're told.

For those who don't know, the internet is a network of connected networks. These networks communicate using the Border Gateway Protocol ( [1]BGP ) to ultimately build up a routing map of the internet, so that when you try to connect to something, your packets of data are sent along the right pipes to the right place. More specifically, the internet consists of networks called autonomous systems (ASes) that [2]advertise their IP address prefixes via routers to neighboring networks using BGP, again to ultimately construct this routing map.

[3]

Malicious ASes can lie to their neighbors, claiming address prefixes they don't own. On March 28, 2022, for example, Russian telecoms provider RTComm.ru started [4]advertising one of Twitter's network prefixes, presumably to intercept Twitter traffic or at least redirect it into a sinkhole, blocking access to the social network.

[5]

[6]

RPKI aspires to prevent prefix hijacking by binding IP addresses to ASes using digital signatures called ROAs (Route Origin Authorizations). Only about 40 percent of all IP address blocks have RPKI certificates and only about 27 percent verify them, [7]according to ATHENE .

But where deployed, RPKI provides ASes with the ability to validate the IP prefix advertisements of other ASes. Using ROV (Route Origin Validation), BGP routers may classify routes as valid or invalid. But when an ROV isn't available from network publication points, the BGP router considers the route unknown and RPKI isn't used for routing decisions.

[8]

This design choice – prioritizing network reachability over security – represents the source of the vulnerability, the ATHENE researchers say.

In [9]research [PDF] presented earlier this year at both the Usenix and Black Hat security conferences, Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Shulman, and Michael Waidner describe an attack called "Stalloris."

The attack requires adversarial control of an RPKI publication point – a router or network – something within the reach of state-level adversaries and other sophisticated miscreants. The adversarial RKPI source is set up to answer requests as slowly as possible and to keep the victim looking for information from controlled publication points. As the name suggests, the technique stalls the network route verification process, which ultimately disables RPKI, so no network route validation occurs.

[10]Internet Society recommends development of Solar-System-scale routing framework

[11]The internet's edge routers are all so different. What if we unified them with software?

[12]Watch your MANRS: Akamai, Amazon, Netflix, Microsoft, Google, and pals join internet routing security effort

[13]Make BGP great again, er, no, for the first time: NIST backs internet route security brainwave

"[W]e show that a combination of Stalloris with just a single iteration of low rate off-path packet loss attack suffices to remove the RPKI validation," the researchers explain in their paper. "The idea behind our Stalloris attack is to create a deep delegation path so that the relying party [validating ROAs for the victim] opens RRDP (RPKI Repository Delta Protocol) connections to multiple publication points controlled by the adversary."

Given a scenario in which the adversary wishes to make AS1 accept the hijacked BGP advertisement for AS2, the technique involves identifying the [14]relying party of AS1 and the DNS resolver involved. It also requires identifying the public repository (publication point) that serves RKPI information for AS2.

[15]

With the relying party of AS1 and the publication point of AS2 known, the attacker then prevents the relying party from communicating with the RKPI repository of AS2. This has to be done repeatedly so cached records to be removed from the DNS resolvers' cache.

This low-rate attack gets combined with the Stalloris attack, which is designed to slow the performance of the relying party, in order to reduce the number of low-rate attack iterations to disable RKPI protection.

Using low rate bursts synchronized with queries from the relying party to find RPKI publication points, the attacker can effectively take RPKI protection out of the picture, forcing the target network to make routing decisions based on unvalidated information.

See the above paper for the full technical details; we're just summarizing here so you get the idea this is a non-trivial attack for well-placed and resourced snoopers. Think of it as either an interesting design challenge to overcome, or a possible means of attack some way down the line in future.

"In our measurements we found 47 percent of the publication points to be vulnerable to rate-limiting downgrade attacks," the paper says. "This corresponds to 60 percent of the RPKI protected IPv4 address space in the Internet."

The boffins say that at the start of 2021, all popular products used by networks to validate RPKI certificates were vulnerable and that they notified product makers about the attack. Presumably, some of the mitigations suggested by the researchers – limiting delegation chains, rethinking how "unknown" routes are handled, etc. – have been implemented by makers of network equipment.

But ATHENE isn't certain how broadly its recommendations have been implemented. "We have not measured how many updated their systems already," a spokesperson said in an email. "We know that the developers integrated patches into the relying party software (except for software of RIPE NCC which is no longer maintained) to prevent the attacks."

Google at least says it has implemented defenses. "Google has protections in place that protect against this threat on our RPKI infrastructure," a spokesperson told The Register .

But with about [16]60 percent of IP address blocks lacking RPKI , network route hijacking remains a risk. ®

Get our [17]Tech Resources



[1] https://book.systemsapproach.org/scaling/global.html?highlight=bgp#interdomain-routing-bgp

[2] https://www.cs.princeton.edu/courses/archive/fall17/cos561/assignments/BGP/Tutorial/Background.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y0NEdF6xBxglk4-loEo8fAAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://isc.sans.edu/diary/28488

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0NEdF6xBxglk4-loEo8fAAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y0NEdF6xBxglk4-loEo8fAAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.athene-center.de/en/news/news/rpki-is-insecure-mechanism-for-internet-security-b-1510

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y0NEdF6xBxglk4-loEo8fAAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.usenix.org/system/files/sec22-hlavacek.pdf

[10] https://www.theregister.com/2022/09/20/ipnsig_solar_system_routing_framework/

[11] https://www.theregister.com/2022/08/26/network_edge/

[12] https://www.theregister.com/2020/03/31/manrs_cdns/

[13] https://www.theregister.com/2018/09/06/nist_bgp_rpki/

[14] https://blog.apnic.net/2021/03/22/rpki-relying-party-synchronization-behaviour/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y0NEdF6xBxglk4-loEo8fAAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://rpki-monitor.antd.nist.gov/

[17] https://whitepapers.theregister.com/



A certain old cat had made his home in the alley behind Gabe's bar for some
time, subsisting on scraps and occasional handouts from the bartender. One
evening, emboldened by hunger, the feline attempted to follow Gabe through
the back door. Regrettably, only the his body had made it through when
the door slammed shut, severing the cat's tail at its base. This proved too
much for the old creature, who looked sadly at Gabe and expired on the spot.
Gabe put the carcass back out in the alley and went back to business.
The mandatory closing time arrived and Gabe was in the process of locking up
after the last customers had gone. Approaching the back door he was startled
to see an apparition of the old cat mournfully holding its severed tail out,
silently pleading for Gabe to put the tail back on its corpse so that it could
go on to the kitty afterworld complete.
Gabe shook his head sadly and said to the ghost, "I can't. You know
the law -- no retailing spirits after 2:00 AM."