Routing-Verification-as-a-Service (RVaaS): Trustworthy Routing Despite Insecure Providers
Liron Schiff, Kashyap Thimmaraju, Stefan Schmid

TL;DR
This paper introduces RVaaS, a low-cost, efficient service that enables users to verify and trust their network routing paths even when network providers are potentially compromised or malicious.
Contribution
It presents a novel framework leveraging SDN features to detect misbehavior and ensure trustworthy routing despite insecure or compromised providers.
Findings
RVaaS can detect routing misbehavior effectively.
The approach combines passive monitoring, logical verification, and in-band testing.
It maintains provider autonomy while ensuring routing trustworthiness.
Abstract
Computer networks today typically do not provide any mechanisms to the users to learn, in a reliable manner, which paths have (and have not) been taken by their packets. Rather, it seems inevitable that as soon as a packet leaves the network card, the user is forced to trust the network provider to forward the packets as expected or agreed upon. This can be undesirable, especially in the light of today's trend toward more programmable networks: after a successful cyber attack on the network management system or Software-Defined Network (SDN) control plane, an adversary in principle has complete control over the network. This paper presents a low-cost and efficient solution to detect misbehaviors and ensure trustworthy routing over untrusted or insecure providers, in particular providers whose management system or control plane has been compromised (e.g., using a cyber attack). We…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
