Skip to main content

Showing 1–2 of 2 results for author: Hlavacek, T

Searching in archive cs. Search in all archives.
.
  1. arXiv:2303.11772  [pdf, other

    cs.NI cs.CR

    Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet

    Authors: Tomas Hlavacek, Haya Shulman, Niklas Vogel, Michael Waidner

    Abstract: IP prefix hijacks allow adversaries to redirect and intercept traffic, posing a threat to the stability and security of the Internet. To prevent prefix hijacks, networks should deploy RPKI and filter bogus BGP announcements with invalid routes. In this work we evaluate the impact of RPKI deployments on the security and resilience of the Internet. We aim to understand which networks filter invali… ▽ More

    Submitted 21 March, 2023; originally announced March 2023.

    Comments: Accepted for USENIX Security '23

  2. arXiv:2205.06064  [pdf, other

    cs.CR cs.NI

    Stalloris: RPKI Downgrade Attack

    Authors: Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Shulman, Michael Waidner

    Abstract: We demonstrate the first downgrade attacks against RPKI. The key design property in RPKI that allows our attacks is the tradeoff between connectivity and security: when networks cannot retrieve RPKI information from publication points, they make routing decisions in BGP without validating RPKI. We exploit this tradeoff to develop attacks that prevent the retrieval of the RPKI objects from the publ… ▽ More

    Submitted 12 May, 2022; originally announced May 2022.

    Journal ref: 31th USENIX Security Symposium (USENIX Security 22), 2022