RiPKI:RPKI 在 Web 生态系统中部署的悲剧故事
网络与互联网体系结构
2015-11-03 v3 密码学与安全
摘要
Web 内容交付是互联网上最重要的服务之一。对网站的访问通常通过 TLS 进行保护。然而,这种安全模型未考虑网络层的前缀劫持,这可能导致流量黑洞或透明拦截。因此,为了实现全面的安全性和服务可用性,需要额外的保护机制,例如最近部署的资源公钥基础设施(RPKI),以防止网络对流量的劫持。本文论证了两个观点。首先,现代 Web 托管实践使得路由保护面临挑战,因为服务器倾向于分布在许多不同的网络中,且往往具有不可预测的客户端重定向策略;其次,我们需要更好地理解为何保护机制未被部署。为此,我们实证探索了 Web 托管基础设施与 RPKI 部署之间的关系。矛盾的是,我们发现不太受欢迎的网站比知名网站更有可能受到保护。令人担忧的是,我们发现许多大规模 CDN 不支持 RPKI,从而使它们的客户面临风险。这促使我们探讨运营商不愿部署 RPKI 的商业原因,这可能有助于指导未来关于改善互联网安全的研究。
引用
@article{arxiv.1408.0391,
title = {RiPKI: The Tragic Story of RPKI Deployment in the Web Ecosystem},
author = {Matthias Wählisch and Robert Schmidt and Thomas C. Schmidt and Olaf Maennel and Steve Uhlig and Gareth Tyson},
journal= {arXiv preprint arXiv:1408.0391},
year = {2015}
}
备注
Previous arXiv version of this paper has been published under the title "When BGP Security Meets Content Deployment: Measuring and Analysing RPKI-Protection of Websites", Proc. of Fourteenth ACM Workshop on Hot Topics in Networks (HotNets), New York:ACM, 2015