ROV-MI: Large-Scale, Accurate and Efficient Measurement of ROV Deployment

Wenqi Chen,Zhiliang Wang,Dongqi Han,Chenxin Duan,Xia Yin,Jiahai Yang,Xingang Shi
DOI: https://doi.org/10.14722/ndss.2022.24214
2022-01-01
Abstract:Securing inter-domain routing systems of the Internet from illegitimate prefix annoucements has been a great concern for the researchers and network operators.After the failure of many BGP (Border Gateway Protocol) security enhancement mechanisms to achieve extensive deployment, it is encouraging to see that the deployment of RPKI (Resource Public Key Infrastructure) is gradually increasing worldwide.For a deeper understanding of the impact of RPKI, many studies have been devoted to measuring the deployment of RPKI, including the deployment of ROA (Route Origin Authorization) and ROV (Route Origin Validation).Unlike the measurement of ROA deployment which can be directly derived from the data in RPKI repository, the measurement of ROV deployment requires more sophisticated measurement and inference techniques.However, existing work has limited measurement range, and the inference methods are either inaccurate or inefficient.In this paper, we propose a new framework, ROV-MI, for the measurement of ROV deployment, which consist of a largescale measurement infrastructure driven by in-the-wild RPKI invalid prefixes in the control plane to detect the filtering of these invalid updates with active probing in the data plane, and an efficient and accurate inference algorithm based on Bayesian inference techniques.We implement ROV-MI for measuring real-world ROV deployment and compare it to prior works, and the results show that ROV-MI can accurately infer ROV adoption of ∼10 times more ASes (Autonomous Systems) with less than 20% of the execution time compared to current stateof-the-art methods.
What problem does this paper attempt to address?