Lurking at the core of all modern internet traffic is a protocol that few properly understand and even fewer know how to actually secure.
Border Gateway Protocol (BGP) is the core routing protocol that enables the internet to function, but it has inherent security vulnerabilities that can be exploited by bad actors to hijack routes, intercept traffic or cause widespread outages. BGP enables the internet's decentralized networks to exchange routing information and connect seamlessly. However, it was designed decades ago with little built-in security. The current state of BGP security is an area of significant concern and ongoing efforts to improve. Even the U.S. government is getting involved.
The Federal Communications Commission (FCC), led by Chairwoman Jessica Rosenworcel, has unveiled a new proposal aimed at bolstering the security of BGP. “It is vital that communication over the internet remains secure,” Rosenworce saidl. “Although there have been efforts to help mitigate BGP's security risks since its original design, more work needs to be done.”
The FCC is proposing that U.S. based broadband providers including AT & T, Comcast and Verizon be required to file regular reports on the BGP security and efforts to improve it.
BGP: A history of vulnerability BGP hijacks have occurred in the past, where attackers falsely advertise ownership of IP address blocks, potentially intercepting traffic or causing outages.
A notable 2018 incident redirected cryptocurrency site traffic to steal funds. The National Cybersecurity Strategy has identified BGP security as a “pervasive concern,” citing the protocol's lack of mechanisms to validate route origination claims.
An FCC Fact Sheet on BGP risks specifically called out a Facebook outage in October 2021 which lasted five hours.
“Facebook’s five-hour global outage in October 2021 was caused in part by a failure of its BGP routing which removed routes to its authoritative Domain Name System servers and resulted in more than 1.2 trillion person-minutes of service unavailability,” the FCC stated. “To its users, it was as if Facebook, and its other services such as Messenger and Instagram, disappeared from the Internet. ”
To improve BGP security, technologies like Resource Public Key Infrastructure (RPKI) and Route Origin Validation (ROV) have emerged. RPKI allows cryptographic verification of the legitimate origin Autonomous System for a given IP address block. Industry groups like MANRS (Mutually Agreed Norms for Routing Security) promote adopting such BGP security best practices among network operators globally.
However, adoption has been relatively slow, especially among smaller networks and in certain regions. The decentralized nature of the internet makes enforcing consistent BGP security practices challenging across tens of thousands of networks.
In steps the FCC The FCC proposal is all about trying to make sure proper steps are being taken by U.S.-based carriers to secure BGP.
The FCC seeks to collect data to assess the reasonability of providers' BGP security efforts and determine if further actions are needed to protect American networks and internet traffic.
If implemented the proposal would do the following:
- Require all broadband providers to develop confidential plans detailing their BGP security measures, including RPKI implementation.
- Mandate the nine largest broadband providers to file these plans with the FCC and submit quarterly public reports on their RPKI deployment progress.
“The most effective approach to improving routing security is through a coordinated, collaborative effort by the global community of network operators,” the Internet Society stated. “Unfortunately, the FCC’s threatened regulation would severely undermine this effort.”
The FCC directive is still at the proposal stage, a formal vote is currently expected in early June.
Comments