Abstract
We analyze the properties of 712 prefixes that appeared in Spamhaus’ Don’t Route Or Peer (DROP) list over a nearly three-year period from June 2019 to March 2022. We show that attackers are subverting multiple defenses against malicious use of address space, including creating fraudulent Internet Routing Registry records for prefixes shortly before using them. Other attackers disguised their activities by announcing routes with spoofed origin ASes consistent with historic route announcements, and in one case, with the ASN in a Route Origin Authorization. We quantify the substantial and actively-exploited attack surface in unrouted address space, which warrants reconsideration of RPKI eligibility restrictions by RIRs, and reconsideration of AS0 policies by both operators and RIRs.
Author supplied keywords
Cite
CITATION STYLE
Oliver, L., Akiwate, G., Luckie, M., Du, B., & Claffy, K. C. (2022). Stop, DROP, and ROA: Effectiveness of Defenses through the lens of DROP. In Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC (pp. 730–737). Association for Computing Machinery. https://doi.org/10.1145/3517745.3561454
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.