‹ Back
20 November 2013

New Internet Society Project Aims to Learn: Is Your Internet Routing Secure and Resilient?

Andrei Robachevsky
By Andrei RobachevskySenior Director, Technology Programmes

You might have seen a recent analysis by Renesys of some sophisticated prefix hijacking increasingly happening in the Internet. I think many of us heard about the Pakistan-YouTube incident and similar misconfigurations, which are in fact a form of a DoS attack. But what Renesys discovered is something different. "Why settle for simple denial of service, when you can instead steal a victim’s traffic, take a few milliseconds to inspect or modify it, and then pass it along to the intended recipient?" – they wrote in the blog.

But that is probably happening to other networks, not yours… Are you sure?

It is possible that routing incidents disguise themselves as other types of outages. A customer call related to loss of connectivity may or may not be a result of a prefix hijack. Research shows that many of the routing incidents last only 30 minutes. By the time a network administrator looks into the case, the incident is gone!

Do we know how much risk is associated with "unprotected" routing, or routing by rumor as it happens frequently in the Internet today? To assess this, we must know not only the frequency of the incidents, but also the impact they cause. And we feel that last bit is completely missing. Risks are often ignored, or accepted, providing little incentive for operators to implement security enhancements.

To tackle this problem the Internet Society, in partnership with BGPmon, has started a project called the "Routing Resilience Survey." This effort is based on the collection of incident data related to routing resilience to provide a statistically representative picture of these incidents and their impacts, as a basis for risk assessment and global trend analysis.

We would like to invite network operators to join this effort. You can find more information about this project here:

https://www.internetsociety.org/rrs/

For participating network operators, the project will help answering questions like:

  • What happens with my prefixes elsewhere in the global Internet?
  • What impact can routing misconfigurations have on my network?
  • How "safe" is the global routing system?

One important thing I'd like to mention here is related to confidentiality. We understand the sensitivity of some of the data involved in this effort. Therefore, the Internet Society is committed to ensuring participant-specific information remains confidential. All data collected will be stored on Internet Society servers. Any public information or analyses will be fully anonymized.

This is a six-month effort. After the project is successfully completed we will publish a report presenting the findings, statistical data and trends. We'll also be happy to present the results at various network operator meetings.

To participate, please send a request for the creation of your account to [email protected]. In the request, please indicate your AS number. You may also include AS numbers of your customers for whom you would like to monitor and classify related security incidents.

We hope you will join this effort.

‹ Back

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related articles

Community Networks 17 August 2021

Register for the Fifth Annual Indigenous Connectivity Summit

In its second year as a virtual event, the Indigenous Connectivity Summit will take place on 12-15 October 2021....

Growing the Internet 7 July 2021

We Can’t Achieve the Sustainable Development Goals without the Internet

The Internet is a critical enabler for sustainable development. It unlocks human capabilities and provides the platform upon which...

About Internet Society 2 June 2021

The Opportunity Your Future Needs: How I Helped Build the Internet and My Career

Have you ever wondered how you can change the course of the Internet? Do you want to share your...

Encryption 1 June 2021

How Do Surveillance Laws Impact the Economy?

In 2018 the Australian parliament passed the “TOLA” Act, expanding the government's powers to bypass digital data protections, and...

Community Networks 22 September 2021

At the 2021 Asia-Pacific Community Networks Summit: Innovating Policymaking to Connect the Unconnected

Asia-Pacific, home to over half the world’s population, is the largest and most diverse region of the globe. Four...

Technology 20 September 2021

The Week in Internet News: Internet Service Through Beams of Light

Light speed Internet: The BBC has a story about an Alphabet X (formerly Google X) project to provide Internet...

Mutually Agreed Norms for Routing Security (MANRS) 15 September 2021

New MANRS Equipment Vendor Program Launched To Improve Internet Routing Security

Today, we’re announcing a new MANRS Equipment Vendor Program. Founding participants include global leaders in network equipment Arista, Cisco,...

Join the conversation with Internet Society members around the world