Microsoft plans to improve internet routing security with a series of steps recommended by a global cloud provider initiative.

The new actions build on earlier routing security efforts that Microsoft undertook including its work with the Cybersecurity Tech Accord, an initiative co-led with Facebook.

Microsoft originally joined the Mutually Agreed Norms for Routing Security (MANRS) initiative, and thus committed to a set of routing security actions, in 2019. Today, it committed to implementing new steps defined by the MANRS Cloud and CDN program including resource public key infrastructure (RPKI) origin validation and route object validation. It will also work with its peer networks and registries to help partners implement these steps.

RPKI is a public key infrastructure framework used to secure Border Gateway Protocol (BGP) routes’ origin information. This is important because BGP hijacking can lead to distributed denial of service (DDoS) attacks and stolen data. Microsoft has signed all BGP routes announced by its Autonomous System Number (ASNs) — these are internet protocol routing prefixes that Microsoft owns. It also updated its peering policy and committed to implement RPKI filtering with all of its internet peers by mid 2021.

Route object validation involves using the public internet routing registries (IRRs) to validate all incoming routes. Microsoft already updated all of its records in RADb, and now is working with its peer networks to update route records in public IRRs. Internally, Microsoft also developed and deployed a global Route Anomaly Detection and Remediation (RADAR) system, which detects and mitigates in real-time route hijacks and route leaks on the internet.

Customers using internet service providers, internet exchange partners, and software-defined cloud interconnect providers that have joined the Azure Peering Service can also register to receive RADAR information and receive alerts if the system detects a route anomaly.

Microsoft’s Ongoing Routing Security Moves

Microsoft has been a leader in the routing security charge, and today’s commitments follow several steps the cloud provider has taken to address internet routing security challenges over the years. In addition to joining MANRS, Microsoft also implemented that framework into its operations. And the first official action by the Cybersecurity Tech Accord was to endorse MANRS as part of a larger routing security effort.

The Cybersecurity Tech Accord and MANRS also established a working group to determine how companies beyond network operators and internet exchange providers can contribute to routing security.

Microsoft President Brad Smith announced the Cybersecurity Tech Accord at the RSA security conference in 2018. It’s a pledge by participating companies to protect their customers from attacks by cybercriminals and nation states, and to not help governments launch cyberattacks.