PPASPA: Aumentando a Segurança do Roteamento da Internet com Autorizações de Provedores por Prefixo

  • Sthefany C. Duquini UFMS
  • Pedro de B. Marcos FURG
  • Ítalo Cunha UFMG
  • Ronaldo A. Ferreira UFMS

Resumo


O ASPA (Autonomous System Provider Authorization) é um mecanismo recente para validação de rotas na Internet que permite um sistema autônomo (AS) publicar objetos assinados indicando quais provedores estão autorizados a anunciar seus prefixos. Entretanto, como as autorizações são definidas por AS, o mecanismo é pouco flexível em cenários com múltiplos provedores e políticas distintas por prefixo. Este trabalho apresenta PPASPA, uma extensão de ASPA que permite associar autorizações específicas a prefixos e que amplia a proteção para situações práticas não contempladas no modelo original. PPASPA foi implementado no software de roteamento BIRD, preservando a lógica de validação de AS-path do ASPA e modificando apenas o mecanismo de identificação dos provedores autorizados a anunciar um prefixo com política específica. A avaliação com dados sintéticos e dados inspirados em traces reais mostra que os custos computacionais introduzidos por PPASPA são baixos, o que pode viabilizar e facilitar sua ampla adoção na Internet.

Referências

Azimov, A., Bogomazov, E., Bush, R., Patel, K., Snijders, J., and Sriram, K. (2025). BGP AS PATH Verification Based on Autonomous System Provider Authorization (ASPA) Objects. Internet-Draft draft-ietf-sidrops-aspa-verification-22, IETF. Work in Progress.

Azimov, A., Uskov, E., Bush, R., Snijders, J., Housley, R., and Maddison, B. (2024). A Profile for Autonomous System Provider Authorization. Internet-Draft draft-ietf-sidrops-aspa-profile-18, IETF. Work in Progress.

Blunk, L., Damas, J., O’Donoghue, F., Gittings, B., Johns, M. S., and Sobrinho, J. L. (2005). Routing Policy Specification Language next generation (RPSLng). RFC 4012, IETF.

Borchert, O., Lee, K., Sriram, K., Montgomery, D., Gleichmann, P., and Adalier, M. (2021). Bgp secure routing extension (bgp-srx): Reference implementation and test tools for emerging bgp security standards. Technical Report NIST TN 2060, National Institute of Standards and Technology.

Bush, R. and Austein, R. (2017). The Resource Public Key Infrastructure (RPKI) to Router Protocol, Version 1. RFC 8210, IETF.

Butler, K., Farley, T., McDaniel, P., and Rexford, J. (2004). A survey of bgp security. ACM, draft version, 5:1–35.

Butler, K., Farley, T. R., McDaniel, P., and Rexford, J. (2010). A survey of BGP security issues and solutions. Proceedings of the IEEE, 98(1):100–122.

CZ.NIC (2026). Bird internet routing daemon. Acessado em: 26 de abr. de 2026.

Flechier, M., Heusse, M., and Duda, A. (2026). PAVA: BGP AS PATH Validation by Querying ASes about Their Relationships. Internet-Draft draft-flechier-sidrops-pava-01, IETF. Work in Progress.

Furuness, J., Morris, C., Morillo, R., Kasiliya, A., Wang, B., and Herzberg, A. (2025). Securing BGP ASAP: ASPA and other Post-ROV Defenses. In Network and Distributed System Security (NDSS) Symposium 2025. Internet Society.

Gao, L. and Rexford, J. (2001). Stable internet routing without global coordination. IEEE/ACM Transactions on Networking, 9(6):681–692.

Giotsas, V., Luckie, M., Huffaker, B., and Claffy, K. (2014). Inferring complex as relationships. In Proceedings of the 2014 Conference on Internet Measurement Conference, pages 23–29, New York, NY, USA. ACM.

Guo, Y., Wang, X., Xu, K., Liu, Z., and Li, Q. (2025). A Profile for Route Path Authorizations (RPAs). Internet-Draft draft-guo-sidrops-rpa-profile-00, IETF. Work in Progress.

Jin, Y., Scott, C., Dhamdhere, A., Giotsas, V., Krishnamurthy, A., and Shenker, S. (2019). Stable and practical as relationship inference with problink. In 16th USENIX Symposium on Networked Systems Design and Implementation (NSDI 19), pages 581–598. USENIX Association.

Kastanakis, S., Giotsas, V., Livadariu, I., and Suri, N. (2023). Replication: 20 years of inferring interdomain routing policies. In Proceedings of the 2023 ACM on Internet Measurement Conference, IMC ’23, pages 16–29, New York, NY, USA. Association for Computing Machinery.

Khadka, S. K. (2025). A first look at the adoption of bgp-based ddos scrubbing services. [link]. RIPE Labs, accessed from the article page.

Khadka, S. K., Bayhan, S., Holz, R., and Hesselman, C. (2026). Detecting and characterizing ddos scrubbing from global bgp routing: Insights from five leading scrubbers. In Passive and Active Measurement, volume 16477 of Lecture Notes in Computer Science, pages 17–43. Springer, Cham.

Lepinski, M. and Sriram, K. (2017). BGPsec Protocol Specification. RFC 8205.

NIST (2026). Robust Inter-Domain Routing. Acessado em 10 maio 2026.

Rekhter, Y., Li, T., and Hares, S. (2006). A Border Gateway Protocol 4 (BGP-4). RFC 4271, IETF.

Rekhter, Y., Li, T., Karrenberg, D., Terpstra, J., and Yu, J. (1999). Routing Policy Specification Language (RPSL). RFC 2622, IETF.

Rodday, N., Cunha, I., Bush, R., Katz-Bassett, E., Rodosek, G. D., Schmidt, T. C., and Wählisch, M. (2024). The resource public key infrastructure (RPKI): A survey on measurements and future prospects. IEEE Transactions on Network and Service Management, 21(2):2353–2373.

Testart, C., Wolff, J., Gouda, D., and Fontugne, R. (2024). Identifying current barriers in RPKI adoption. Technical report, Georgia Institute of Technology and Tufts University and IIJ Research Laboratory. Pre-print manuscript.

University of Oregon (2026). University of Oregon Route Views Project. Acessado em: 27 de janeiro de 2026.

Xu, K., Jiang, S., Guo, Y., and Wang, X. (2025). BGP AS PATH Verification Based on Route Path Authorizations (RPA) Objects. Internet-Draft draft-xu-sidrops-rpa-verification-01, IETF. Work in Progress.
Publicado
01/09/2026
DUQUINI, Sthefany C.; MARCOS, Pedro de B.; CUNHA, Ítalo; FERREIRA, Ronaldo A.. PPASPA: Aumentando a Segurança do Roteamento da Internet com Autorizações de Provedores por Prefixo. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 945-960. DOI: https://doi.org/10.5753/sbseg.2026.28923.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 3 > >>