Ben Du

dblp:267/4528 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0002-4685-0532ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 4 first-author · 5 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 Sublet Your Subnet: Inferring IP Leasing in the Wild
abstract
IPv4 addresses have become a commodity with monetary value since the exhaustion of unallocated IPv4 space. This led to the rise of a secondary market for buying, selling, and leasing IPv4 addresses. While prior work has studied the IPv4 transfer behavior, the IPv4 leasing ecosystem remains largely unexplored. In this paper, we analyze the IPv4 leasing ecosystem by designing a methodology to infer leased address space for all RIRs and study its impact on routing and hosting security. We infer that 4.1% of all advertised IPv4 prefixes (0.9% of routed v4 address space) were leased in April 2024. Our method achieves 98% precision when evaluated against our validated dataset. Finally, we show that leased address space is five times more likely to be abused compared to non-leased space.
Ben Du, Romain Fontugne, Cecilia Testart, Alex C. Snoeren, K. C. Claffy
IMC1
2023 IRRegularities in the Internet Routing Registry
abstract
The Internet Routing Registry (IRR) is a set of distributed databases used by networks to register routing policy information and to validate messages received in the Border Gateway Protocol (BGP). First deployed in the 1990s, the IRR remains the most widely used database for routing security purposes, despite the existence of more recent and more secure alternatives. Yet, the IRR lacks a strict validation standard and the limited coordination across different database providers can lead to inaccuracies. Moreover, it has been reported that attackers have begun to register false records in the IRR to bypass operators' defenses when launching attacks on the Internet routing system, such as BGP hijacks. In this paper, we provide a longitudinal analysis of the IRR over the span of 1.5 years. We develop a workflow to identify irregular IRR records that contain conflicting information compared to different routing data sources. We identify 34,199 irregular route objects out of 1,542,724 route objects from November 2021 to May 2023 in the largest IRR database and find 6,373 to be potentially suspicious.
Ben Du, Katherine Izhikevich, Sumanth Rao, Gautam Akiwate, Cecilia Testart, Alex C. Snoeren, K. C. Claffy
IMC1
2023 Poster: Taking the Low Road: How RPKI Invalids Propagate
abstract
The Border Gateway Protocol (BGP) includes no mechanism to verify the correctness of routing information exchanged between networks. To defend against unauthorized use of address space, the IETF developed the Resource Public Key Infrastructure (RPKI), a cryptographically attested database system that facilitates validation of BGP messages. Networks can use RPKI to check whether the Autonomous System (AS) at the origin of the AS path in a BGP announcement is authorized to originate the IP prefixes being announced.
Ben Du, Cecilia Testart, Romain Fontugne, Alex C. Snoeren, K. C. Claffy
SIGCOMM1
2022 Mind your MANRS: measuring the MANRS ecosystem
abstract
Mutually Agreed Norms on Routing Security (MANRS) is an industry-led initiative to improve Internet routing security by encouraging participating networks to implement a series of mandatory or recommended actions. MANRS members must register their IP prefixes in a trusted routing database and use such information to prevent propagation of invalid routing information. MANRS membership has increased significantly in recent years, but the impact of the MANRS initiative on the overall Internet routing security remains unclear. In this paper, we provide the first independent look into the MANRS ecosystem by using publicly available data to analyze the routing behavior of participant networks. We quantify MANRS participants' level of conformance with the stated requirements, and compare the behavior of MANRS and non-MANRS networks. While not all MANRS members fully comply with all required actions, we find that they are more likely to implement routing security practices described in MANRS actions. We assess the relevance of the MANRS effort in securing the overall routing ecosystem. We found that as of May 2022, over 83% of MANRS networks were conformant to the route filtering requirement by dropping BGP messages with invalid information according to authoritative records, and over 95% were conformant to the routing information facilitation requirement, registering their resources in authoritative databases.
Ben Du, Cecilia Testart, Romain Fontugne, Gautam Akiwate, Alex C. Snoeren, K. C. Claffy
IMC1
2022 Stop, DROP, and ROA: effectiveness of defenses through the lens of DROP
abstract
We analyze the properties of 712 prefixes that appeared in Spamhaus' Don't Route Or Peer (DROP) list over a nearly three-year period from June 2019 to March 2022. We show that attackers are subverting multiple defenses against malicious use of address space, including creating fraudulent Internet Routing Registry records for prefixes shortly before using them. Other attackers disguised their activities by announcing routes with spoofed origin ASes consistent with historic route announcements, and in one case, with the ASN in a Route Origin Authorization. We quantify the substantial and actively-exploited attack surface in unrouted address space, which warrants reconsideration of RPKI eligibility restrictions by RIRs, and reconsideration of AS0 policies by both operators and RIRs.
Leo Oliver, Gautam Akiwate, Matthew J. Luckie, Ben Du, K. C. Claffy
IMC4
2022 IRR Hygiene in the RPKI Era
Ben Du, Gautam Akiwate, Thomas Krenc, Cecilia Testart, Alexander Marder, Bradley Huffaker, Alex C. Snoeren, K. C. Claffy
PAM1