{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:26:39Z","timestamp":1750307199314,"version":"3.41.0"},"reference-count":32,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2011,12,1]],"date-time":"2011-12-01T00:00:00Z","timestamp":1322697600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Technol."],"published-print":{"date-parts":[[2011,12]]},"abstract":"<jats:p>The global economy and society increasingly depends on computer networks linked together by the Internet. The importance of computer networks reaches far beyond the telecommunications sector since they have become a critical factor for many other crucial infrastructures and markets. With threats mounting and security incidents becoming more frequent, concerns about network security grow.<\/jats:p>\n          <jats:p>It is an acknowledged fact that some of the most fundamental network protocols that make the Internet work are exposed to serious threats. One of them is the Border Gateway Protocol (BGP) which determines how Internet traffic is routed through the topology of administratively independent networks that the Internet is comprised of. Despite the existence of a steadily growing number of BGP security proposals, to date none of them has been adopted.<\/jats:p>\n          <jats:p>Using a precise definition of BGP robustness we experimentally show that the degree of robustness is distributed unequally across the administrative domains of the Internet, the so-called Autonomous Systems (ASes). The experiments confirm the intuition that the contribution ASes are able to make towards securing the correct working of the inter-domain routing infrastructure by deploying countermeasures against routing attacks differ depending on their position in the AS topology. We also show that the degree of this asymmetry can be controlled by the choice of the security strategy. We compare the strengths and weaknesses of two fundamentally different approaches in increasing BGP's robustness which we termed ingress and egress detection of false route advertisements and indicate their implications. Our quantitative results have important implications for Internet security policy, in particular with respect to the crucial question where to start the deployment of which type of security scheme in order to maximize the Internet's robustness to routing attacks.<\/jats:p>","DOI":"10.1145\/2049656.2049657","type":"journal-article","created":{"date-parts":[[2011,12,13]],"date-time":"2011-12-13T15:45:47Z","timestamp":1323791147000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Comparing ingress and egress detection to secure interdomain routing"],"prefix":"10.1145","volume":"11","author":[{"given":"Christoph","family":"Goebel","sequence":"first","affiliation":[{"name":"International Computer Science Institute, Berkeley, CA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dirk","family":"Neumann","sequence":"additional","affiliation":[{"name":"Albert-Ludwigs-Universit\u00e4t, Freiburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ramayya","family":"Krishnan","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University, Pittsburgh, PA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,12,12]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2009.2034031"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1159913.1159946"},{"key":"e_1_2_1_3_1","unstructured":"European Union. 2001. Network and information security: Proposal for a European policy approach. http:\/\/ec.europa.eu\/information_society\/eeurope\/2002\/news_library\/pdf_files\/netsec_en.pdf.  European Union. 2001. Network and information security: Proposal for a European policy approach. http:\/\/ec.europa.eu\/information_society\/eeurope\/2002\/news_library\/pdf_files\/netsec_en.pdf."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/963985.963988"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1064009.1064022"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1273445.1273453"},{"key":"e_1_2_1_7_1","unstructured":"CAIDA. 2009. Data Collection at CAIDA. http:\/\/www.caida.org\/data\/.  CAIDA. 2009. Data Collection at CAIDA. http:\/\/www.caida.org\/data\/."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.974527"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Gill V. Heasley J. and Meyer D. 2004. The generalized TTL security mechanism (GTSM). RFC 3682.   Gill V. Heasley J. and Meyer D. 2004. The generalized TTL security mechanism (GTSM). RFC 3682.","DOI":"10.17487\/rfc3682"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS '03)","author":"Goodell G.","key":"e_1_2_1_10_1","unstructured":"Goodell , G. , Aiello , W. , Griffin , T. , Ioannidis , J. , McDaniel , P. , and Rubin , A . 2003. Working around BGP: An incremental approach to improving security and accuracy of interdomain routing . In Proceedings of the Network and Distributed System Security Symposium (NDSS '03) . Goodell, G., Aiello, W., Griffin, T., Ioannidis, J., McDaniel, P., and Rubin, A. 2003. Working around BGP: An incremental approach to improving security and accuracy of interdomain routing. In Proceedings of the Network and Distributed System Security Symposium (NDSS '03)."},{"key":"e_1_2_1_11_1","unstructured":"Heffernan A. 2002. Protection of BGP sessions via the TCP MD5 signature option. RFC 2385.   Heffernan A. 2002. Protection of BGP sessions via the TCP MD5 signature option. RFC 2385."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1015467.1015488"},{"volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS'00)","author":"Kent S.","key":"e_1_2_1_13_1","unstructured":"Kent , S. , Lynn , C. , Mikkelson , J. , and Seo , K . 2000. Secure border gateway protocol (S-BGP): Real world performance and deployment issues . In Proceedings of the Network and Distributed System Security Symposium (NDSS'00) . Kent, S., Lynn, C., Mikkelson, J., and Seo, K. 2000. Secure border gateway protocol (S-BGP): Real world performance and deployment issues. In Proceedings of the Network and Distributed System Security Symposium (NDSS'00)."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/49.839934"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/90.929852"},{"volume-title":"Proceedings of the 18th Annual Joint Conference of the IEEE Computer and Communications Societies. 218 --226","author":"Labovitz C.","key":"e_1_2_1_16_1","unstructured":"Labovitz , C. , Malan , G. , and Jahanian , F . 1999. Origins of internet routing instability . In Proceedings of the 18th Annual Joint Conference of the IEEE Computer and Communications Societies. 218 --226 . Labovitz, C., Malan, G., and Jahanian, F. 1999. Origins of internet routing instability. In Proceedings of the 18th Annual Joint Conference of the IEEE Computer and Communications Societies. 218 --226."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/633025.633027"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/964725.633047"},{"key":"e_1_2_1_19_1","unstructured":"Misel S. 1997. Wow AS 7007&excl; lurlhttp:\/\/www.merit.eduJmail.archives\/nanog\/1997-04\/msg00340.html.  Misel S. 1997. Wow AS 7007&excl; lurlhttp:\/\/www.merit.eduJmail.archives\/nanog\/1997-04\/msg00340.html."},{"key":"e_1_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Murphy S. 2006. BGP security vulnerabilities analysis. RFC 4272.  Murphy S. 2006. BGP security vulnerabilities analysis. RFC 4272.","DOI":"10.17487\/rfc4272"},{"volume-title":"TR2003-440","author":"Nicol D. M.","key":"e_1_2_1_21_1","unstructured":"Nicol , D. M. , Smith , S. W. , and Zhao , M . 2003. Efficientsecurity for BGP route announcements. Tech. rep . TR2003-440 , Dartmouth College. Nicol, D. M., Smith, S. W., and Zhao, M. 2003. Efficientsecurity for BGP route announcements. Tech. rep. TR2003-440, Dartmouth College."},{"key":"e_1_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Odlyzko A. 2003. Economics psychology and sociology of security. http:\/\/www.dtc.umn.edu\/odlyzko\/doc\/econ.psych.security.pdf.  Odlyzko A. 2003. Economics psychology and sociology of security. http:\/\/www.dtc.umn.edu\/odlyzko\/doc\/econ.psych.security.pdf.","DOI":"10.1007\/978-3-540-45126-6_13"},{"key":"e_1_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Rekhter Y. and Li T. 2006. A border gateway protocol 4 (BGP 4). RFC 4271.  Rekhter Y. and Li T. 2006. A border gateway protocol 4 (BGP 4). RFC 4271.","DOI":"10.17487\/rfc4271"},{"volume-title":"Proceedings of the 3rd Workshop on Hot Topics in Networks.","author":"Subramanian L.","key":"e_1_2_1_24_1","unstructured":"Subramanian , L. , Caesar , M. , Ee , C. T. , Handley , M. , Mao , Z. M. , Shenker , S. , and Stoica , I . 2004a. Towards a next generation inter-domain routing protocol . In Proceedings of the 3rd Workshop on Hot Topics in Networks. Subramanian, L., Caesar, M., Ee, C. T., Handley, M., Mao, Z. M., Shenker, S., and Stoica, I. 2004a. Towards a next generation inter-domain routing protocol. In Proceedings of the 3rd Workshop on Hot Topics in Networks."},{"volume-title":"Proceedings of the 1st Symposium on Networked Systems Design and Implementation (NSDl). USENIX, 127--140","author":"Subramanian L.","key":"e_1_2_1_25_1","unstructured":"Subramanian , L. , Roth , V. , Stoica , I. , Shenker , S. , and Katz , R. H . 2004b. Listen and whisper: Security mechanisms for BGP . In Proceedings of the 1st Symposium on Networked Systems Design and Implementation (NSDl). USENIX, 127--140 . Subramanian, L., Roth, V., Stoica, I., Shenker, S., and Katz, R. H. 2004b. Listen and whisper: Security mechanisms for BGP. In Proceedings of the 1st Symposium on Networked Systems Design and Implementation (NSDl). USENIX, 127--140."},{"volume-title":"Proceedings of the 20th Annual Joint Conference of the IEEE Computer and Communications Societies (IEEE INFOCOM'01). 736--742","author":"Tangmunarunkit H.","key":"e_1_2_1_26_1","unstructured":"Tangmunarunkit , H. , Govindan , R. , Shenker , S. , and Estrin , D . 2001. The Impact of Routing Policy on Internet Paths . In Proceedings of the 20th Annual Joint Conference of the IEEE Computer and Communications Societies (IEEE INFOCOM'01). 736--742 . Tangmunarunkit, H., Govindan, R., Shenker, S., and Estrin, D. 2001. The Impact of Routing Policy on Internet Paths. In Proceedings of the 20th Annual Joint Conference of the IEEE Computer and Communications Societies (IEEE INFOCOM'01). 736--742."},{"key":"e_1_2_1_27_1","unstructured":"The President's Critical Infrastructure Protection Board. 2003. The national strategy to secure cyberspace. http:\/\/www.us-cert.gov\/reading_room\/cyberspace_strategy.pdf.  The President's Critical Infrastructure Protection Board. 2003. The national strategy to secure cyberspace. http:\/\/www.us-cert.gov\/reading_room\/cyberspace_strategy.pdf."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00108-5"},{"volume-title":"Proceedings of the Workshop on Hot Topics in Networks (HotNets'06)","author":"Wendlandt D.","key":"e_1_2_1_29_1","unstructured":"Wendlandt , D. , Avramopoulos , I. , Andersen , D. G. , and Rexford , J . 2006. Don't secure routing protocols, secure data delivery . In Proceedings of the Workshop on Hot Topics in Networks (HotNets'06) . Wendlandt, D., Avramopoulos, I., Andersen, D. G., and Rexford, J. 2006. Don't secure routing protocols, secure data delivery. In Proceedings of the Workshop on Hot Topics in Networks (HotNets'06)."},{"key":"e_1_2_1_30_1","unstructured":"White R. 2004. Deployment considerations for secure origin BGP (soBGP). http:\/\/tools.ietf.org\/html\/draft-white-sobgp-architecture-OO.  White R. 2004. Deployment considerations for secure origin BGP (soBGP). http:\/\/tools.ietf.org\/html\/draft-white-sobgp-architecture-OO."},{"volume-title":"Proceedings of the 1st IEEE Workshop on Secure Network Protocols.","author":"Yu H.","key":"e_1_2_1_31_1","unstructured":"Yu , H. , Rexford , J. , and Felten , E. W . 2005. A distributed reputation approach cooperative internet routing protection . In Proceedings of the 1st IEEE Workshop on Secure Network Protocols. Yu, H., Rexford, J., and Felten, E. W. 2005. A distributed reputation approach cooperative internet routing protection. In Proceedings of the 1st IEEE Workshop on Secure Network Protocols."},{"volume-title":"Proceedings of the International Conference on Dependable Systems and Networks (DSN'02)","author":"Zhao X.","key":"e_1_2_1_32_1","unstructured":"Zhao , X. , Pei , D. , Wang , L. , Massey , D. , Mankin , A. , Wu , S. F. , and Zhang , L . 2002. Detection of invalid routing announcement in the internet . In Proceedings of the International Conference on Dependable Systems and Networks (DSN'02) . IEEE Computer Society, 59--68. Zhao, X., Pei, D., Wang, L., Massey, D., Mankin, A., Wu, S. F., and Zhang, L. 2002. Detection of invalid routing announcement in the internet. In Proceedings of the International Conference on Dependable Systems and Networks (DSN'02). IEEE Computer Society, 59--68."}],"container-title":["ACM Transactions on Internet Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2049656.2049657","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2049656.2049657","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:06:12Z","timestamp":1750241172000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2049656.2049657"}},"subtitle":["An experimental analysis"],"short-title":[],"issued":{"date-parts":[[2011,12]]},"references-count":32,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2011,12]]}},"alternative-id":["10.1145\/2049656.2049657"],"URL":"https:\/\/doi.org\/10.1145\/2049656.2049657","relation":{},"ISSN":["1533-5399","1557-6051"],"issn-type":[{"type":"print","value":"1533-5399"},{"type":"electronic","value":"1557-6051"}],"subject":[],"published":{"date-parts":[[2011,12]]},"assertion":[{"value":"2008-02-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-01-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2011-12-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}