MaxLength Considered Harmful to the RPKI

MaxLength Considered Harmful to the RPKI
复制标题

MaxLength 被认为对 RPKI 有害

DOI:
10.1145/3143361.3143363
复制
发表时间:
2017
期刊:
Proceedings of the 13th International Conference on emerging Networking EXperiments and Technologies
影响因子:
--
通讯作者:
S. Goldberg
S. Goldberg
中科院分区:
--
文献类型:
--
作者:
Y. Gilad;Omar Sagga;S. Goldberg

文献摘要

被引文献

相似文献

用户便利性和强大的安全性通常是不一致的,大多数安全应用程序需要在这两个(通常是对立的)目标之间找到某种平衡。资源公钥基础设施(RPKI)是一种建立在域间路由之上的安全基础设施,也不能幸免于此问题。RPKI使用maxLength属性来减少必须显式记录在其加密对象中的信息量。MaxLength还允许运营商轻松地重新配置其网络,而无需修改其RPKI对象。然而,我们的网络测量表明,maxLength属性在安全性和用户方便性之间取得了错误的平衡。因此,我们认为运营商应该避免使用maxLength。我们提供运营建议并开发软件,使运营商能够在不增加安全成本的情况下获得maxLength的许多好处。
User convenience and strong security are often at odds, and most security applications need to find some sort of balance between these two (often opposing) goals. The Resource Public Key Infrastructure (RPKI), a security infrastructure built on top of interdomain routing, is not immune to this issue. The RPKI uses the maxLength attribute to reduce the amount of information that must be explicitly recorded in its cryptographic objects. MaxLength also allows operators to easily reconfigure their networks without modifying their RPKI objects. Our network measurements, however, suggest that the maxLength attribute strikes the wrong balance between security and user convenience. We therefore believe that operators should avoid using maxLength. We give operational recommendations and develop software that allow operators to reap many of the benefits of maxLength without its security costs.