BGP Flashcards

1
Q

IP Prefix Hijacking

A
  • malicious AS originates a prefix it does not own

- subprefix hijacking: originate longer (more specific prefix)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

BGP Protocol

A
  • TCP messages over port 179

- OPEN, UPDATE, KEEP-ALIVE, NOTIFICATION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

BGP Interception

A
  • Hijack traffic and then send it to leg. AS
    1. selectively announce prefix to some neighbors
    2. use bgp poisoning
    3. use bgp communities to ensure that announcement only reaches certain ASes
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BGP poisoning

A

Hijack some prefix by originating target prefix, but add a neighbor AS in the AS path, so that this AS will reject the path and can act as leg. path to the target prefix for interception attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Get TLS Certificate

A

request cert but hijack traffic in which CA tries to validate HTML challenge to attackers server. Obviously attacker can prove control of this server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

RPKI

A

origin authentication for prefix announcements

  • AS checks origin of prefix against secure database (RPKI) of Route Origin Authenticatinos (ROAs)
  • origin auth. is not enough. malicious AS can append itself to a existing path
  • verification of signatures is done offline
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

BGPSec

A
  • Secures the AS-PATH attribute
  • origin authentication + cryptographic sig. to prove that path was correctly updated
  • RPKI used to verify AS key material
    ISSUE:
  • AS use legacy BGP and most don’t priorities security
  • performance degradation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Path End Validation

A

additionally to origin auth. store next hop as well in RPKI. Attacker can not directly append itself to the origin and longer routes are usually not taken.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

extensive monitoring

A
  • monitor update messages and prefer routes that agree with the past
  • generate reports or alerts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

OSPF

A
  • Open shortest path first

- Interior gateway protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly