AUTO-UPDATED

Who's running all those tiny RPKI servers?

Independent RPKI publication servers play a critical role in securing Internet routing by allowing network operators to cryptographically authorize IP address prefixes and prevent malicious BGP hijacking attempts.

Key Points

  • Resource Public Key Infrastructure (RPKI) uses Route Origin Authorizations (ROAs) to verify that an Autonomous System (AS) is authorized to announce specific IP address prefixes.
  • While five global Regional Internet Registries (RIRs) manage most RPKI data, a "long tail" of smaller, independent servers exists for operational control, cross-registry management, and research.
  • Researchers analyzed 3,778 ROA objects across 1,163 unique ASes, finding that 91% of these objects are cryptographically valid.
  • Over 50% of analyzed ROAs use the "maxLength" parameter, which can inadvertently increase vulnerability to sub-prefix hijacks if not configured according to RFC 9319 guidelines.
  • The study identified that 19.6% of ROAs using maxLength lack corresponding BGP announcements, creating potential security risks for those specific network segments.

Why it Matters

RPKI is essential for maintaining the integrity of global Internet routing, as it provides a mechanism to detect and block unauthorized traffic redirection. Understanding the diversity of these publication servers helps identify potential security gaps and operational risks that could impact the verifiability and stability of critical online services.
Apnic.net Published by Ties Dirksen
Read original