MIT Libraries logoDSpace@MIT

MIT
View Item 
  • DSpace@MIT Home
  • MIT Libraries
  • MIT Theses
  • Doctoral Theses
  • View Item
  • DSpace@MIT Home
  • MIT Libraries
  • MIT Theses
  • Doctoral Theses
  • View Item
JavaScript is disabled for your browser. Some features of this site may not work without it.

Towards Data-Driven Internet Routing Security

Author(s)
Testart Pacheco, Cecilia Andrea
Thumbnail
DownloadThesis PDF (6.074Mb)
Advisor
Clark, David D.
Terms of use
In Copyright - Educational Use Permitted Copyright MIT http://rightsstatements.org/page/InC-EDU/1.0/
Metadata
Show full item record
Abstract
The Internet infrastructure is critical for the security and reliability of online daily life. The Border Gateway Protocol (BGP), the defacto global routing protocol, was not designed to cope with untrustworthy parties, making BGP vulnerable to misconfigurations and attacks from anywhere in the network. Recently, unintended large-scale misconfigurations caused significant amount of Internet traffic towards major providers to be dropped for hours, and through BGP attacks, perpetrators have stolen millions in fraudulent transactions. Nonetheless, little has changed in operational environments despite the many proposals to increase security by the research, standardization and industry communities. The problem space is complex: it involves multiple stakeholders, with different interests and available resources, and increasingly, geopolitical challenges. Yet, these stakeholders ultimately need to cooperate and coordinate their efforts to improve security. This dissertation proposes a holistic approach to study routing security. It includes the assessment of barriers of adoption of technical proposals to secure BGP, the empirical analysis of exploitations and misconfiguration due to BGP design flaws, as well as the empirical study of the mitigation strategies deployment and benefits. This analysis reveals the extent of misbehavior and misconfiguration in the use of BGP, and the benefit that operational security practices provide. It also discusses this new evidence in the context of tradeoff that have prevented the adoption of routing security. Finally, it provides a set of actions, which could be orchestrated by a bottom-up industry effort or top-down by governments, and directions for future technical work that would encourage collective adoption of security in BGP.
Date issued
2021-09
URI
https://hdl.handle.net/1721.1/139960
Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Publisher
Massachusetts Institute of Technology

Collections
  • Doctoral Theses

Browse

All of DSpaceCommunities & CollectionsBy Issue DateAuthorsTitlesSubjectsThis CollectionBy Issue DateAuthorsTitlesSubjects

My Account

Login

Statistics

OA StatisticsStatistics by CountryStatistics by Department
MIT Libraries
PrivacyPermissionsAccessibilityContact us
MIT
Content created by the MIT Libraries, CC BY-NC unless otherwise noted. Notify us about copyright concerns.