SRv6: Is There Anybody Out There?

Segment routing is a modern form of source-based routing, i.e., a routing technique where all or part of the routing decision is predetermined by the source or a hop on the path. Since initial standardization efforts in 2013, segment routing seems to have garnered substantial industry and operator support. Especially segment routing over IPv6 (SRv6) is advertised as having several advantages for easy deployment and flexibility in operations in networks. Many people, however, argue that the deployment of segment routing and SRv6 in particular poses a significant security threat if not done with the utmost care. In this paper we conduct a first empirical analysis of SRv6 deployment in the Internet. First, we analyze SRv6 behavior in an emulation environment and find that different SRv6 implementations have the potential to leak information to the outside. Second, we search for signs of SRv6 deployment in publicly available route collector data, but could not find any traces. Third, we run large-scale traceroute campaigns to investigate possible SRv6 deployments. In this first empirical study on SRv6 we are unable to find traces of SRv6 deployment even for companies that claim to have it deployed in their networks. This lack of leakage might be an indication of good security practices being followed by network operators when deploying SRv6.

READ FULL TEXT
research
12/29/2020

A Survey on Segment Routing with Emphasis on Use Cases in Large Provider Networks

Segment routing is heralded as important technology innovation in large ...
research
06/11/2020

Peerlock: Flexsealing BGP

BGP route leaks frequently precipitate serious disruptions to interdomai...
research
05/10/2019

Inferring Catchment in Internet Routing

BGP is the de-facto Internet routing protocol for exchanging prefix reac...
research
04/20/2020

Securing Internet Applications from Routing Attacks

Attacks on Internet routing are typically viewed through the lens of ava...
research
10/24/2018

Flexible failure detection and fast reroute using eBPF and SRv6

Segment Routing is a modern variant of source routing that is being grad...
research
10/15/2021

Federated Route Leak Detection in Inter-domain Routing with Privacy Guarantee

In the inter-domain network, a route leak occurs when a routing announce...
research
06/28/2022

Hyper-Specific Prefixes: Gotta Enjoy the Little Things in Interdomain Routing

Autonomous Systems (ASes) exchange reachability information between each...

Please sign up or login with your details

Forgot password? Click here to reset