Creating a Secure Underlay for the Internet
Henry Birge-Lee, Joel Wanner, Grace Cimaszewski, Jonghoon Kwon, Liang, Wang, Francois Wirz, Prateek Mittal, Adrian Perrig, Yixin Sun

TL;DR
This paper proposes a novel architecture called SBAS that creates a secure, federated backbone for Internet routing, integrating secure routing protocols with the existing BGP infrastructure to enhance security against routing attacks.
Contribution
It introduces the SBAS architecture that abstracts a secure routing backbone as a virtual AS, enabling secure route exchange and integration with BGP, demonstrated through real-world deployment and simulations.
Findings
SBAS reduces routing attack threats significantly.
The architecture effectively integrates secure backbone with BGP.
Network operator surveys inform governance and incentives.
Abstract
Adversaries can exploit inter-domain routing vulnerabilities to intercept communication and compromise the security of critical Internet applications. Meanwhile the deployment of secure routing solutions such as Border Gateway Protocol Security (BGPsec) and Scalability, Control and Isolation On Next-generation networks (SCION) are still limited. How can we leverage emerging secure routing backbones and extend their security properties to the broader Internet? We design and deploy an architecture to bootstrap secure routing. Our key insight is to abstract the secure routing backbone as a virtual Autonomous System (AS), called Secure Backbone AS (SBAS). While SBAS appears as one AS to the Internet, it is a federated network where routes are exchanged between participants using a secure backbone. SBAS makes BGP announcements for its customers' IP prefixes at multiple locations (referred…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Traffic and Congestion Control · Internet Traffic Analysis and Secure E-voting · Software-Defined Networks and 5G
