SlideShare ist ein Scribd-Unternehmen logo
1 von 21
Internet Society © 1992–2016
https://www.manrs.org/
Two years of good MANRS
Improving Global Routing Security and Resilience
January 2017
Internet Routing
• About 53,000 networks participate in global Internet routing – with 21,000 being single
“stub” networks (e.g. a small enterprise) and about 7,000 participating in the core Internet
http://www.cidr-report.org/as2.0/
• Routers use Border Gateway Protocol (BGP) to “announce” networks they know about and
to receive route announcements from connected networks.
• Routers build a “routing table” and pick the “best” route when sending a packet, typically
based on the shortest path.
• Routers have Autonomous System Numbers (ASN) uniquely identifying them to all other
routers
http://www.iana.org/assignments/as-numbers/as-numbers.xhtml
http://www.whatismyasn.org/
2
The Problem
• Border Gateway Protocol (BGP) is based on trust
• No built-in validation of the legitimacy of updates
• Chain of trust spans continents
• Lack of reliable resource data
3
Case study: http://bit.ly/youtube-pakistan
7 years later...
https://bgpstream.com/
What’s behind these incidents?
• IP prefix hijack
• AS announces prefix it doesn’t originate
• AS announces more specific prefix than what may be announced by originating AS
• AS announces it can route traffic through shorter route, whether it exists or not
• Packets end-up being forwarded to wrong part of Internet
• Denial-of-Service, traffic interception, or impersonating network or service
• Route leaks
• Similar to prefix hijacking
• Usually not malicious and due to misconfigurations
• IP address spoofing
• Creation of IP packets with false source address
• The root cause of reflection DDoS attacks
7
Are there solutions?
• Yes!
• Prefix and AS-PATH filtering, RPKI, IRR, …
• BGPSEC under development at the IETF
• Whois, Routing Registries and Peering databases
• But…
• Lack of deployment
• Lack of reliable data
8
It is a socio-economic problem –
A tragedy of the Commons
• From a routing perspective, securing one’s own network does not
make it more secure. Network security is in someone else’s hands
• The more hands – the better the security
• Is there a clear, visible and industry supported line between good and
bad?
• A cultural norm
9
A clearly articulated baseline –
a minimum requirement (MCOP)
+
Visible support with commitment
10
Mutually Agreed Norms for Routing Security
(MANRS)
MANRS defines four concrete actions that network
operators should implement
• Technology-neutral baseline for global adoption
MANRS builds a visible community of security-minded
operators
• Promotes culture of collaborative responsibility
11
Good MANRS
• Filtering – Prevent propagation of incorrect routing information
Own announcements and the customer cone
• Anti-spoofing – Prevent traffic with spoofed source IP addresses
Single-homed stub customers and own infra
• Coordination – Facilitate global operational communication and coordination
between network operators
Up-to-date and responsive public contacts
• Global Validation – Facilitate validation of routing information on a global scale
Publish your data, so others can validate
12
MANRS is not (only) a document – it is a
commitment
• The members support the Principles and implement the
majority of the Actions in their networks
• A member becomes a Participant of MANRS, helping to
maintain and improve the document and to promote
MANRS objectives
13
A growing list of participants
14
0
10
20
30
40
50
60
70
80
90
100
2014 2015 2016 2017 (so far)
# of AS
# of AS
Two years of MANRS
15
MANRS members by # of AS’es
0
1000
2000
3000
4000
5000
6000
7000
8000
2014 2015 2016 2017 . . . . . . ?
# of AS
# of AS
You may say we’re dreamers…
16
MANRS members by # of AS’es
MANRS Participants in Africa
• 1,516 ASNs assigned in AfriNIC region
• 443 ASNs in South Africa (ZA)
• 2 ASNs participating in MANRS (0.13%)
• Workonline Communications (AS3271) - 4 actions
• NOOR Data Networks (AS20928) - 3 actions
17
How to bridge this gap?
18
Leveraging market forces and peer pressure
• Developing a better “business case” for MANRS
• MANRS value proposition for your customers and your own network
• Creating a trusted community
• A group with a similar attitude towards security
19
Increasing gravity by making MANRS a
platform for related activities
• Developing better guidance
• MANRS Best Current Operational Practices (BCOP) document:
http://www.routingmanifesto.org/bcop/
• Training/certification programme
• Based on BCOP document and an online module
• Bringing new types of members on board
• IXPs
20
MANRS: How to Sign-Up
• Go to https://www.manrs.org/signup/
• Provide requested information
• Please provide as much detail on how Actions are implemented as possible
• We may ask questions and ask you to run a few tests
• Routing “background check”
• Spoofer https://www.caida.org/projects/spoofer/
• Your answer to “Why did you decide to join?” may be displayed in the
testimonials
• Download the logo and use it
• Become an active MANRS participant
21

Weitere ähnliche Inhalte

Was ist angesagt?

ION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRSION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRSDeploy360 Programme (Internet Society)
 

Was ist angesagt? (20)

ION Belgrade - Closing Slides
ION Belgrade - Closing SlidesION Belgrade - Closing Slides
ION Belgrade - Closing Slides
 
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter PresentationION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
 
Mind Your MANRS - Mutually Agreed Norms for Routing Security
Mind Your MANRS - Mutually Agreed Norms for Routing SecurityMind Your MANRS - Mutually Agreed Norms for Routing Security
Mind Your MANRS - Mutually Agreed Norms for Routing Security
 
ION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRSION Cape Town - Collective Responsibility for Routing Security and MANRS
ION Cape Town - Collective Responsibility for Routing Security and MANRS
 
ION Malta - Opening Slides
ION Malta - Opening SlidesION Malta - Opening Slides
ION Malta - Opening Slides
 
ION Cape Town - Welcome from ISOC Gauteng Chapter
ION Cape Town - Welcome from ISOC Gauteng ChapterION Cape Town - Welcome from ISOC Gauteng Chapter
ION Cape Town - Welcome from ISOC Gauteng Chapter
 
ION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & AccountabilityION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & Accountability
 
ION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internetION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internet
 
ION Malta - IETF Update
ION Malta - IETF UpdateION Malta - IETF Update
ION Malta - IETF Update
 
ION Cape Town - Closing Remarks
ION Cape Town - Closing RemarksION Cape Town - Closing Remarks
ION Cape Town - Closing Remarks
 
ION Bangladesh - Opening Remarks
ION Bangladesh - Opening RemarksION Bangladesh - Opening Remarks
ION Bangladesh - Opening Remarks
 
ION Hangzhou - Keynote: Collaborative Security and an Open Internet
ION Hangzhou - Keynote: Collaborative Security and an Open InternetION Hangzhou - Keynote: Collaborative Security and an Open Internet
ION Hangzhou - Keynote: Collaborative Security and an Open Internet
 
ION Trinidad and Tobago - Opening Slides
ION Trinidad and Tobago - Opening SlidesION Trinidad and Tobago - Opening Slides
ION Trinidad and Tobago - Opening Slides
 
Status of IPv6 in Pakistan
Status of IPv6 in PakistanStatus of IPv6 in Pakistan
Status of IPv6 in Pakistan
 
ION Malta - MANRS Introduction
ION Malta - MANRS IntroductionION Malta - MANRS Introduction
ION Malta - MANRS Introduction
 
ION Cape Town - IETF, Operational Experience, and Africa
ION Cape Town - IETF, Operational Experience, and AfricaION Cape Town - IETF, Operational Experience, and Africa
ION Cape Town - IETF, Operational Experience, and Africa
 
ION Bangladesh - IETF Update
ION Bangladesh - IETF UpdateION Bangladesh - IETF Update
ION Bangladesh - IETF Update
 
ION Hangzhou - Opening Remarks
ION Hangzhou - Opening RemarksION Hangzhou - Opening Remarks
ION Hangzhou - Opening Remarks
 
ION Bangladesh - ISOC Dhaka Chapter Welcome
ION Bangladesh - ISOC Dhaka Chapter WelcomeION Bangladesh - ISOC Dhaka Chapter Welcome
ION Bangladesh - ISOC Dhaka Chapter Welcome
 
ION Islamabad - Opening Remarks
ION Islamabad - Opening RemarksION Islamabad - Opening Remarks
ION Islamabad - Opening Remarks
 

Ähnlich wie ION Durban - MANRS Introduction

ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...Deploy360 Programme (Internet Society)
 
Two years of good MANRS
Two years of good MANRSTwo years of good MANRS
Two years of good MANRSAPNIC
 
Reliable Resource Data
Reliable Resource DataReliable Resource Data
Reliable Resource DataAPNIC
 
MANRS - Introduction to Internet Routing Security
MANRS - Introduction to Internet Routing SecurityMANRS - Introduction to Internet Routing Security
MANRS - Introduction to Internet Routing SecurityObika Gellineau
 
How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...APNIC
 
PLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It Together
PLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It TogetherPLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It Together
PLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It TogetherPROIDEA
 
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...Internet Society
 
ARM 7 - ISOC: MANRS, Security and resilience of global routing system
ARM 7 - ISOC: MANRS, Security and resilience of global routing systemARM 7 - ISOC: MANRS, Security and resilience of global routing system
ARM 7 - ISOC: MANRS, Security and resilience of global routing systemAPNIC
 
AFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAPNIC
 
Routing is at Risk - Let’s secure it together
Routing is at Risk - Let’s secure it togetherRouting is at Risk - Let’s secure it together
Routing is at Risk - Let’s secure it togetherAPNIC
 
Collective responsibility for security and resilience of the global routing s...
Collective responsibility for security and resilience of the global routing s...Collective responsibility for security and resilience of the global routing s...
Collective responsibility for security and resilience of the global routing s...APNIC
 
The Internet Ecosystem
The Internet EcosystemThe Internet Ecosystem
The Internet EcosystemRIPE NCC
 
IPv6 Adoption by ASEAN Government Agencies
IPv6 Adoption by ASEAN Government AgenciesIPv6 Adoption by ASEAN Government Agencies
IPv6 Adoption by ASEAN Government AgenciesAPNIC
 
Summary paa s_countryreport_meshingo.pptx.pptx
Summary paa s_countryreport_meshingo.pptx.pptxSummary paa s_countryreport_meshingo.pptx.pptx
Summary paa s_countryreport_meshingo.pptx.pptxMeshingo Jack
 
Lao ICT Expo 2019: Your IP, Your Network
Lao ICT Expo 2019: Your IP, Your NetworkLao ICT Expo 2019: Your IP, Your Network
Lao ICT Expo 2019: Your IP, Your NetworkAPNIC
 
Government
Government Government
Government APNIC
 
Government Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkagesGovernment Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkagesAPNIC
 

Ähnlich wie ION Durban - MANRS Introduction (20)

ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
 
Two years of good MANRS
Two years of good MANRSTwo years of good MANRS
Two years of good MANRS
 
Reliable Resource Data
Reliable Resource DataReliable Resource Data
Reliable Resource Data
 
MANRS - Introduction to Internet Routing Security
MANRS - Introduction to Internet Routing SecurityMANRS - Introduction to Internet Routing Security
MANRS - Introduction to Internet Routing Security
 
How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...How can we work together to improve security and resilience of the global rou...
How can we work together to improve security and resilience of the global rou...
 
PLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It Together
PLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It TogetherPLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It Together
PLNOG 21: Andrei Robachevsky - Routing Is At Risk. Let's Secure It Together
 
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
 
Improving routing security through concerted action
Improving routing security through concerted actionImproving routing security through concerted action
Improving routing security through concerted action
 
ARM 7 - ISOC: MANRS, Security and resilience of global routing system
ARM 7 - ISOC: MANRS, Security and resilience of global routing systemARM 7 - ISOC: MANRS, Security and resilience of global routing system
ARM 7 - ISOC: MANRS, Security and resilience of global routing system
 
AusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRSAusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRS
 
AFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressingAFSIG 2023: Internet routing and addressing
AFSIG 2023: Internet routing and addressing
 
Routing is at Risk - Let’s secure it together
Routing is at Risk - Let’s secure it togetherRouting is at Risk - Let’s secure it together
Routing is at Risk - Let’s secure it together
 
Collective responsibility for security and resilience of the global routing s...
Collective responsibility for security and resilience of the global routing s...Collective responsibility for security and resilience of the global routing s...
Collective responsibility for security and resilience of the global routing s...
 
The Internet Ecosystem
The Internet EcosystemThe Internet Ecosystem
The Internet Ecosystem
 
IPv6 Adoption by ASEAN Government Agencies
IPv6 Adoption by ASEAN Government AgenciesIPv6 Adoption by ASEAN Government Agencies
IPv6 Adoption by ASEAN Government Agencies
 
Summary paa s_countryreport_meshingo.pptx.pptx
Summary paa s_countryreport_meshingo.pptx.pptxSummary paa s_countryreport_meshingo.pptx.pptx
Summary paa s_countryreport_meshingo.pptx.pptx
 
Lao ICT Expo 2019: Your IP, Your Network
Lao ICT Expo 2019: Your IP, Your NetworkLao ICT Expo 2019: Your IP, Your Network
Lao ICT Expo 2019: Your IP, Your Network
 
Government
Government Government
Government
 
Government Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkagesGovernment Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkages
 
PACE-IT: Introduction_to Routing Concepts (part 2) - N10 006
PACE-IT: Introduction_to Routing Concepts (part 2) - N10 006PACE-IT: Introduction_to Routing Concepts (part 2) - N10 006
PACE-IT: Introduction_to Routing Concepts (part 2) - N10 006
 

Mehr von Deploy360 Programme (Internet Society)

ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...
ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...
ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...Deploy360 Programme (Internet Society)
 

Mehr von Deploy360 Programme (Internet Society) (14)

ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success StoriesION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
 
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
 
ION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSECION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSEC
 
ION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLSION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLS
 
ION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: FinlandION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: Finland
 
ION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 TransitionION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 Transition
 
ION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for youION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for you
 
ION Durban - NAT64/DNS64 Experiments and the NAT64Check Tool
ION Durban - NAT64/DNS64 Experiments and the NAT64Check ToolION Durban - NAT64/DNS64 Experiments and the NAT64Check Tool
ION Durban - NAT64/DNS64 Experiments and the NAT64Check Tool
 
ION Durban - DNSSEC, and Why We Can't Avoid It
ION Durban - DNSSEC, and Why We Can't Avoid ItION Durban - DNSSEC, and Why We Can't Avoid It
ION Durban - DNSSEC, and Why We Can't Avoid It
 
ION Durban - IPv6 Case Study (Liquid Telecom)
ION Durban - IPv6 Case Study (Liquid Telecom)ION Durban - IPv6 Case Study (Liquid Telecom)
ION Durban - IPv6 Case Study (Liquid Telecom)
 
ION Costa Rica - About the IETF and How to Get Involved
ION Costa Rica - About the IETF and How to Get InvolvedION Costa Rica - About the IETF and How to Get Involved
ION Costa Rica - About the IETF and How to Get Involved
 
ION Costa Rica - Closing Slides
ION Costa Rica - Closing SlidesION Costa Rica - Closing Slides
ION Costa Rica - Closing Slides
 
ION Costa Rica - Validacion en el origen
ION Costa Rica - Validacion en el origenION Costa Rica - Validacion en el origen
ION Costa Rica - Validacion en el origen
 
ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...
ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...
ION Costa Rica - Setting the Scene: IPv6 Deployment in Costa Rica and Latin A...
 

Kürzlich hochgeladen

08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 

Kürzlich hochgeladen (20)

08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 

ION Durban - MANRS Introduction

  • 1. Internet Society © 1992–2016 https://www.manrs.org/ Two years of good MANRS Improving Global Routing Security and Resilience January 2017
  • 2. Internet Routing • About 53,000 networks participate in global Internet routing – with 21,000 being single “stub” networks (e.g. a small enterprise) and about 7,000 participating in the core Internet http://www.cidr-report.org/as2.0/ • Routers use Border Gateway Protocol (BGP) to “announce” networks they know about and to receive route announcements from connected networks. • Routers build a “routing table” and pick the “best” route when sending a packet, typically based on the shortest path. • Routers have Autonomous System Numbers (ASN) uniquely identifying them to all other routers http://www.iana.org/assignments/as-numbers/as-numbers.xhtml http://www.whatismyasn.org/ 2
  • 3. The Problem • Border Gateway Protocol (BGP) is based on trust • No built-in validation of the legitimacy of updates • Chain of trust spans continents • Lack of reliable resource data 3
  • 6.
  • 7. What’s behind these incidents? • IP prefix hijack • AS announces prefix it doesn’t originate • AS announces more specific prefix than what may be announced by originating AS • AS announces it can route traffic through shorter route, whether it exists or not • Packets end-up being forwarded to wrong part of Internet • Denial-of-Service, traffic interception, or impersonating network or service • Route leaks • Similar to prefix hijacking • Usually not malicious and due to misconfigurations • IP address spoofing • Creation of IP packets with false source address • The root cause of reflection DDoS attacks 7
  • 8. Are there solutions? • Yes! • Prefix and AS-PATH filtering, RPKI, IRR, … • BGPSEC under development at the IETF • Whois, Routing Registries and Peering databases • But… • Lack of deployment • Lack of reliable data 8
  • 9. It is a socio-economic problem – A tragedy of the Commons • From a routing perspective, securing one’s own network does not make it more secure. Network security is in someone else’s hands • The more hands – the better the security • Is there a clear, visible and industry supported line between good and bad? • A cultural norm 9
  • 10. A clearly articulated baseline – a minimum requirement (MCOP) + Visible support with commitment 10
  • 11. Mutually Agreed Norms for Routing Security (MANRS) MANRS defines four concrete actions that network operators should implement • Technology-neutral baseline for global adoption MANRS builds a visible community of security-minded operators • Promotes culture of collaborative responsibility 11
  • 12. Good MANRS • Filtering – Prevent propagation of incorrect routing information Own announcements and the customer cone • Anti-spoofing – Prevent traffic with spoofed source IP addresses Single-homed stub customers and own infra • Coordination – Facilitate global operational communication and coordination between network operators Up-to-date and responsive public contacts • Global Validation – Facilitate validation of routing information on a global scale Publish your data, so others can validate 12
  • 13. MANRS is not (only) a document – it is a commitment • The members support the Principles and implement the majority of the Actions in their networks • A member becomes a Participant of MANRS, helping to maintain and improve the document and to promote MANRS objectives 13
  • 14. A growing list of participants 14
  • 15. 0 10 20 30 40 50 60 70 80 90 100 2014 2015 2016 2017 (so far) # of AS # of AS Two years of MANRS 15 MANRS members by # of AS’es
  • 16. 0 1000 2000 3000 4000 5000 6000 7000 8000 2014 2015 2016 2017 . . . . . . ? # of AS # of AS You may say we’re dreamers… 16 MANRS members by # of AS’es
  • 17. MANRS Participants in Africa • 1,516 ASNs assigned in AfriNIC region • 443 ASNs in South Africa (ZA) • 2 ASNs participating in MANRS (0.13%) • Workonline Communications (AS3271) - 4 actions • NOOR Data Networks (AS20928) - 3 actions 17
  • 18. How to bridge this gap? 18
  • 19. Leveraging market forces and peer pressure • Developing a better “business case” for MANRS • MANRS value proposition for your customers and your own network • Creating a trusted community • A group with a similar attitude towards security 19
  • 20. Increasing gravity by making MANRS a platform for related activities • Developing better guidance • MANRS Best Current Operational Practices (BCOP) document: http://www.routingmanifesto.org/bcop/ • Training/certification programme • Based on BCOP document and an online module • Bringing new types of members on board • IXPs 20
  • 21. MANRS: How to Sign-Up • Go to https://www.manrs.org/signup/ • Provide requested information • Please provide as much detail on how Actions are implemented as possible • We may ask questions and ask you to run a few tests • Routing “background check” • Spoofer https://www.caida.org/projects/spoofer/ • Your answer to “Why did you decide to join?” may be displayed in the testimonials • Download the logo and use it • Become an active MANRS participant 21

Hinweis der Redaktion

  1. Limited scope: MANRS use case: the network and topology e.g. ensures correctness of their own announcements and announcements from their customers to adjacent networks with prefix and AS-path granularity e.g. enables source address validation for at least single-homed stub customer networks, their own end-users and infrastructure e.g. maintain globally accessible up-to-date contact information.