Saturday, April 28, 2007

BGP Security, ISP Core Security Resources (BGP, Border Gateway Protocol / Advanced Internet Routing)

BGP Security, ISP Core Security Resources (BGP, Border Gateway Protocol / Advanced Internet Routing)

BGP Articles, Links, Whitepapers BGP Presentations Incident Handling Resources DDoS Mitigation Techniques BGP Tools, Utilities, Software2005 SP Infrastructure Security Survey Results Presentation, Craig Labovitz, Danny McPherson, NANOG-35 Meeting, Oct 2005A Blueprint for Improving the Robustness of Internet Routing Georgos Siganos, Michalis Faloutsos, 2005A PKI for IP Address Space and AS Numbers Stephen Kent, RIPE-52 Meeting, Apr 2006A Secure BGP Implementation (bgpd) Presentation, Henning Brauer, Oct 2004A Survey of BGP Security (Draft version) Kevin Butler, Toni Farley, Patrick McDaniel, Jennifer Rexford, 2005Address Space & AS Number Hijacking Presentation, Leslie Nobile, Leo Vegoda, RIPE-48 Meeting, May 2004Aggregated Path Authentication for Efficient BGP Security Meiyuan Zhao, Sean W. Smith, David M. Nicol, Nov 2005Alerting Prefix Owners of Hijacks in Near-Real Time Mohit Lad, NANOG-37 Meeting, Jun 2006APNIC Trial of Certification of IP Addresses and ASes Presentation, Geoff Huston, RIPE-51 Meeting, Oct 2005Application Note: Securing BGP on Juniper Routers Guidelines, Maintained by Stephen GillAuthentication for TCP-based Routing and Management Protocols Ron Bonica, Andrew Lange, Sriram Viswanathan, Brian Weis, NANOG-37 Meeting, Jun 2006Auto-Detecting Hijacked Prefixes Presentation, Geoff Huston, RIPE-50 Meeting, May 2005BGP/MPLS Layer 3 VPNs Presentation, Ina Minei, NANOG-30 Meeting, Feb 2004BGP Attack Trees: Real World Examples Presentation, Sue Hares, NANOG-28, Jun 2003BGP Filtering - Myths, Legends and Reality: Peer Filtering in the Modern Backbone Jim Deleskie, Tom Scholl, Todd Underwood, Alin Popescu, NANOG-35 Meeting, Oct 2005BGP Flow Specification Deployment Experience Derek Gassen, Raul Lozano, Danny McPherson, Craig Labovitz, NANOG-38 Meeting, Oct 2006BGP Flow Specification Deployment ExperienceL Flowspec Examples Derek Gassen, Raul Lozano, Danny McPherson, Craig Labovitz, NANOG-38 Meeting, Oct 2006BGP MD5: Good, Bad, Ugly? Tom Scholl, NANOG-39 Meeting, Feb 2007BGP Prefix Filtering Cisco ISP Security Bootcamp, 2002BGP Security Russ Housley, RIPE-52 Meeting, Apr 2006BGP Security (Powerpoint)Presentation, Russ White, 2001-2003BGP Security Requirements - An Overview of Current Work in the IETF (1) Tony Tauber et al, NANOG-33 Meeting, Feb 2005BGP Security Requirements - An Overview of Current Work in the IETF (2) Tony Tauber et al, NANOG-33 Meeting, Feb 2005BGP Security Update Presentation, Barry Raveendran Greene, NANOG-25 Meeting, Jun 2002BGP Security, Just Add Peers! (Powerpoint)Presentation, Rob Thomas, May 2002BGP Security Vulnerabilities Analysis IETF RFC 4272, S. Murphy, Jan 2006BGP Support for TTL Security Check - Cisco IOS Documentation, Cisco Systems, 2003BGP Vulnerability Testing: Separating Fact from FUD v1.00 Presentation, Sean Convery, Matthew Franz, NANOG-28 Meeting, Jun 2003BlackHole Route Server and Tracking Traffic on an IP Network (How to Track a DoS Attack) Chris Morrow, Brian Gemberling, 2001Building an Early Warning System in a Service Provider Network Presentation, Nicolas Fischbach, Black Hat Briefings Europe, 2004Comparing BGP/MPLS and IPSec VPNs Whitepaper, Gary Alterson, Sans InfoSec Reading Room, Jan 2002Configuring BGP to Block Denial-of-Service Attacks IETF RFC 3882, Doughan Turk, Sep 2004Effects of Worms on Internet Routing Stability Article, Ido Dubrawsky, SecurityFocus InFocus Article, Jun 2003Efficient Security for BGP Route Announcements Whitepaper, David M. Nicol et al, Feb 2003Efficient Security Mechanisms for Routing Protocols Whitepaper, Yih-Chun Hu et al, Network and Distributed System Security Symposium Symposium, 2003Evolving the Core: Deployment Challenges and the Internet Presentation, J. Scott Marcus, NANOG-32 Meeting, Oct 2004Flooding Attacks by Exploiting Persistent Forwarding Loops Jianhong Xia, Lixin Gao, Teng Fei, NANOG-36 Meeting, Feb 2006Generic Threats to Routing Protocols IETF RFC 4593, A. Barbir, S. Murphy, Y. Yang, Oct 2006How to Allow Customers to Blackhole their own Traffic Chris Morrow, Brian Gemberling, et al, 2002-2004How to Securely use SNMP on a BGP/MPLS VPN Network Whitepaper, Guillaume Tamboise, Sans InfoSec Reading Room, Apr 2002Identifying Compromised Hosts by Analyzing Real-Time Blacklists Presentation, Rick Wesson, NANOG-35 Meeting, Oct 2005IETF Operational Security Capabilities for IP Network Infrastructure Working Group (OPSEC) Working Group, Internet Engineering Task Force (IETF)IETF Routing Protocol Security Requirements Working Group (RPSEC) Working Group, Internet Engineering Task Force (IETF)IETF Secure Inter-Domain Routing Working Group (SIDR) Working Group, Internet Engineering Task Force (IETF)Implications of Securing Backbone Router Infrastructure (Powerpoint)Presentation, Ryan McDowell, NANOG-31 Meeting, May 2004Improving the Security and Robustness of Internet Routing Presentation, Georgos Siganos, Michalis Faloutsos, RIPE-51 Meeting, Oct 2005Infrastructure Security Presentation, Nicolas Fischbach, RIPE-46 Meeting, Sep 2003Ingress Filtering for Multihomed Networks IETF RFC 3704 / BCP 84, F. Baker, P. Savola, Mar 2004Ingress Prefix Filter Template; for eBGP sessions with other ISPs (Loose mode) Guidelines, Maintained by Barry Greene et alIngress Prefix Filter Template; for eBGP sessions with other ISPs (Strict mode) Guidelines, Maintained by Barry Greene et alInternet Hardening via Routing Registries Larry Blunk, Manish Karir, 2005IP Backbone Security (Powerpoint)Presentation, Nicolas Fischbach, Sébastien Lacoste-Seris, Black Hat Briefings, Jul 2002IP Hijacking Presentation, David J. Bowie, MIT Security Camp, 2003Is the Border Gateway Protocol Safe? Whitepaper, Sargon Elias, Sans InfoSec Reading Room, Apr 2003ISP Security 101 - Peers Working Together to Battle Attacks on the Net (Powerpoint)Barry Greene, Roland Dobbins, NANOG-36 Meeting, Feb 2006JunOS Loose ISP Prefix Filter Template Maintained by Stephen GillJunOS Strict ISP Filter Prefix Template Maintained by Stephen GillKey Change Strategies for TCP-MD5 IETF RFC 4808, S. Bellovin, Mar 2007Known Threats to Routing Protocols Presentation, Dennis Beard, Yi Yang, Nov 2002Layer 3 MPLS/VPN Security Considerations Whitepaper, Cisco, Oct 2003Listen and Whisper: Security Mechanisms for BGP Whitepaper, Lakshminarayanan Subramanian et al, Mar 2004Listen and Whisper: Security Mechanisms for BGP Presentation, L. Subramanian, V. Roth, I. Stoica, S. Shenker, and R.H. Katz, NANOG-30 Meeting, Feb 2004Marcus Sachs on Securing the Homeland (Full mp3-interview here) Article, Dan Farber, ZDnet, Jun 2005Mining Anomalies in Network-Wide Flow Data (Powerpoint)Presentation, Anukool Lakhina, Mark Crovella, Christophe Diot, NANOG-35 Meeting, Oct 2005Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing IETF RFC 2827 / BCP 38, P. Ferguson, D. Senie, May 2000Operational Security Current Practices Merike Kaeo et al, NANOG-37 Meeting, Jun 2006Operational Security Requirements for Large ISP IP Network Infrastructure IETF RFC 3871, G. Jones, Ed., Sep 2004Options for Blackhole and Discard Routing - Tutorial Presentation, Joseph M. Soricelli, Wayne Gustavus, NANOG-32 Meeting, Oct 2004Origin Authentication in Interdomain Routing Whitepaper, William Aiello, John Ioannidis, Patrick McDaniel, Oct 2003Overloading BGP for VPN Can Be Harmful InformIT.com Article by Ruixi Yuan, Jan 2002PHAS: A Prefix Hijack Alert System (Presentation) Dan Massey, Yan Chen, Mohit Lad, Lixia Zhang, Beichuan Zhang, NANOG-38 Meeting, Oct 2006PHAS: A Prefix Hijack Alert System (Paper) Mohit Lad, Dan Massey, Dan Pei, Yiguo Wu, Beichuan Zhang, Lixia Zhang, Jul 2006Position Paper: Operational Requirements for Secured BGP Steven M. Bellovin, John Ioannidis, Randy Bush, Mar 2005Pretty Good BGP and the Internet Alert Registry Josh Karlin, Stephanie Forrest, Jennifer Rexford, NANOG-37 Meeting, Jun 2006Pretty Secure BGP (psBGP) Tao Wan, Evangelos Kranakis, P.C. van Oorschot, 2005Protecting Routing Infrastructures from Denial-of-Service using Cooperative Intrusion Detection Whitepaper, Steven Cheung, Karl N. LevittProtecting the BGP Routes to Top Level DNS Servers Presentation, Daniel Massey, Randy Bush, et al, NANOG-25 Meeting, Jun 2002Remote Triggering Black Hole Filtering Whitepaper, Cisco, 2002Routing Policy System Security IETF RFC 2725, C. Villamizar et al, Dec 1999Routing Protocols Security Working Group Website Website, Maintained by Russ White et alRouting Security Presentation, Steven M. Bellovin, Jun 2003SBGP - Secure BGP Presentation, Steven M. Bellovin, Jun 2003Secure BGP Project (S-BGP) Website, BBN Technologies, Internetwork Research DepartmentSecure BGP Template for Cisco IOS Guidelines, Maintained by Rob Thomas, updated regularlySecure BGP Template for Juniper JunOS Guidelines, Maintained by Stephen Gill, updated regularlySecure Border Gateway Protocol (Secure-BGP) Whitepaper, Stephen Kent, Charles Lynn, Karen Seo, IEEE Journal on Selected Areas in Communications, Apr 2000Secure Border Gateway Protocol (S-BGP) Presentation, Charles Lynn, Network and Distributed Systems Security Symposium, Feb 1999Secure Cisco IOS Template Guidelines, Maintained by Rob ThomasSecure Juniper JunOS Template Guidelines, Maintained by Stephen GillSecure Origin BGP (soBGP) Presentation, David Cook, RIPE-45 Meeting, May 2003Secure Protocols for the Routing Infrastructure (SPRI) Initiative - A Roadmap Sparta/DHS.gov, Sep 2006Secure Riverstone ROS Template Guidelines, Maintained by Andy WaldenSecuring a Core Network - Presentation Presentation, Michael Behringer, Christian Panigl, RIPE-49 Meeting, Sep 2004Securing a Core Network - Discussion Presentation, Michael Behringer, Christian Panigl, RIPE-49 Meeting, Sep 2004Securing BGP on Juniper Routers Guidelines, Stephen Gill, Apr 2003Securing Inter-Domain Routing Column, Geoff Huston, Mar 2005Securing Routing - An ISP's Perspective Column, Geoff Huston, Feb 2005Securing the Border Gateway Protocol: A Status Update Whitepaper, Stephen T. Kent, 2003Securing the Border Gateway Protocol: S-BGP Article, Cisco Internet Protocol Journal (IPJ), Stephen T. Kent, Sep 2003Securing the Border Gateway Protocol: SoBGP (Secure Origin BGP) Article, Cisco Internet Protocol Journal (IPJ), Russ White, Sep 2003Securing the Routing Infrastructure: Status and Request for Comments Sandra Murphy, NANOG-39 Meeting, Feb 2007Security and Accuracy of Interdomain Routing Presentation, Geoffrey Goodell, et al, NANOG-27 Meeting, Feb 2003Security and Predictability: Two Missing Pieces in BGP Whitepaper, Lakshmi Subramanian, Workshop on Internet Routing Evolution and Design, Oct 2003Security and Predictability: Two Missing Pieces in BGP (Powerpoint)Presentation, Lakshmi Subramanian, Workshop on Internet Routing Evolution and Design, Oct 2003Security in Core Networks - An Overview Presentation, Eric Vyncke, Cisco, 2003Security Issues Affecting Internet Transit Points and Backbone Providers (Powerpoint)Presentation, Batz, Black Hat Briefings, Jul 1999Security Toolsets for ISP Defense - Backbone Practices Presentation, Timothy A. Battles, NANOG-32 Meeting, Oct 2004Seguridad en BGP (in Spanish)Article, Saulo Barajas, 2003Short-Lived Prefix Hijacking on the Internet Peter Boothe, James Hiebert, Randy Bush, NANOG-36 Meeting, Feb 2006$tea£ing with BGP Presentation, Stephan Dugan, Black Hat Briefings, Feb 2003Threats Relating to IPv6 Multihoming Solutions IETF RFC 4218, E. Nordmark, T. Li, Oct 2005Understanding the Network-Level Behavior of Spammers Anirudh Ramachandran, Nick Feamster, Sep 2006Using Link Cuts to Attack Internet Routing Steven M. Bellovin, Emden R. Gansner, May 2003Using X.509 v3 Resource Certificates in RIR Resource Allocations Geoff Huston, RIPE-53 Meeting, Oct 2006What S-BGP Means for RIPE & RIPE Members Presentation, Stephen Kent, RIPE-45 Meeting, May 2003Where the Wild Things Are: BGP Threats Presentation, Steven M. Bellovin, Jun 2003Working Around BGP: An Incremental Approach to Improving Security and Accuracy of Interdomain Routing Whitepaper, Geoffrey Goodell et al, 2003
Practical BGPRuss White et al
BGPIljitsch Van Beijnum
BGP Design and ImplementationRandy Zhang
Troubleshooting IP Routing ProtocolsZaheer Aziz, Johnson Liu, Abe Martey, Faraz Shamim, Johnson Lui
Optimal Routing DesignRuss White, Alvaro Retana, Don Slice