How Effective is Multiple-Vantage-Point Domain Control Validation?
Grace Cimaszewski, Henry Birge-Lee, Liang Wang, Jennifer Rexford,, Prateek Mittal

TL;DR
This paper evaluates the effectiveness of multiple-vantage-point domain control validation (multiVA) in defending against BGP hijacking, using a comprehensive analysis framework applied to Let's Encrypt's deployment, revealing significant resilience improvements and optimization opportunities.
Contribution
It introduces the first analysis framework for measuring multiVA security in real-world network configurations and applies it to quantify Let's Encrypt's deployment resilience.
Findings
Let's Encrypt's multiVA offers 88% median resilience against BGP hijacks.
RPKI deployment enhances security by 15% even in partial deployment.
Further configuration optimizations can increase resilience to over 99%.
Abstract
Multiple-vantage-point domain control validation (multiVA) is an emerging defense for mitigating BGP hijacking attacks against certificate authorities. While the adoption of multiVA is on the rise, little work has quantified its effectiveness against BGP hijacks in the wild. We bridge the gap by presenting the first analysis framework that measures the security of a multiVA deployment under real-world network configurations (e.g., DNS and RPKI). Our framework accurately models the attack surface of multiVA by 1) considering the attacks on DNS nameservers involved in domain validation, 2) considering deployed practical security techniques such as RPKI, 3) performing fine-grained internet-scale analysis to compute multiVA resilience (i.e., how difficult it is to launch a BGP hijack against a domain and get a bogus certificate under multiVA). We use our framework to perform a rigorous…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Internet Traffic Analysis and Secure E-voting · Access Control and Trust
