Peerlock: Flexsealing BGP

06/11/2020
by   Tyler McDaniel, et al.
0

BGP route leaks frequently precipitate serious disruptions to interdomain routing. These incidents have plagued the Internet for decades while deployment and usability issues cripple efforts to mitigate the problem. Peerlock, introduced in 2016, addresses route leaks with a new approach. Peerlock enables filtering agreements between transit providers to protect their own networks without the need for broad cooperation or a trust infrastructure. We outline the Peerlock system and one variant, Peerlock-lite, and conduct live Internet experiments to measure their deployment on the control plane. Our measurements find evidence for significant Peerlock protection between Tier 1 networks in the peering clique, where 48 reveal that many other networks also deploy filters against Tier 1 leaks. To guide further deployment, we also quantify Peerlock's impact on route leaks both at currently observed levels and under hypothetical future deployment scenarios via BGP simulation. These experiments reveal present Peerlock deployment restricts Tier 1 leak export to 10 simulated leaks. Strategic additional Peerlock-lite deployment at all large ISPs (fewer than 1 peering clique as deployed, completely mitigates 80 leaks.

READ FULL TEXT

page 8

page 11

page 12

research
05/09/2022

SRv6: Is There Anybody Out There?

Segment routing is a modern form of source-based routing, i.e., a routin...
research
12/14/2020

Anatomy of Multipath BGP Deployment in a Large ISP Network

Multipath routing is useful for networks to achieve load sharing among m...
research
03/21/2023

Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet

IP prefix hijacks allow adversaries to redirect and intercept traffic, p...
research
10/15/2021

Federated Route Leak Detection in Inter-domain Routing with Privacy Guarantee

In the inter-domain network, a route leak occurs when a routing announce...
research
10/19/2022

Kirin: Hitting the Internet with Millions of Distributed IPv6 Announcements

The Internet is a critical resource in the day-to-day life of billions o...
research
12/18/2020

Simulation Environment for Safety Assessment of CEAV Deployment in Linden

This report presents a simulation environment for pre-deployment testing...
research
08/06/2018

Quantifying Deployability & Evolvability of Future Internet Architectures via Economic Models

Emerging new applications demand the current Internet to provide new fun...

Please sign up or login with your details

Forgot password? Click here to reset