Tomas Hlavacek

dblp:223/6748 · DBLP profile ↗
← Back
8ranked-venue papers
7as first author
5since 2021 · last 2023
0009-0006-9239-9232ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 6 first-author · 4 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2023 Beyond Limits: How to Disable Validators in Secure Networks
abstract
Relying party validator is a critical component of RPKI: it fetches and validates signed authorizations mapping prefixes to their owners. Routers use this information to block bogus BGP routes.
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner
SIGCOMM1
2023 Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet
Tomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael Waidner
USENIX Security Symposium1
2022 Behind the Scenes of RPKI
abstract
Best practices for making RPKI resilient to failures and attacks recommend using multiple URLs and certificates for publication points as well as multiple relying parties. We find that these recommendations are already supported by 63% of the ASes with RPKI.
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner
CCS1
2022 Smart RPKI Validation: Avoiding Errors and Preventing Hijacks
Tomas Hlavacek, Haya Schulmann, Michael Waidner
ESORICS (1)1
2022 Stalloris: RPKI Downgrade Attack
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner
USENIX Security Symposium1
2020 DISCO: Sidestepping RPKI's Deployment Barriers
Tomas Hlavacek, Ítalo S. Cunha, Yossi Gilad, Amir Herzberg, Ethan Katz-Bassett, Michael Schapira, Haya Schulmann
NDSS1
2018 Practical Experience: Methodologies for Measuring Route Origin Validation
abstract
Performing Route Origin Validation (ROV) to filter BGP announcements, which contradict Route Origin Authorizations (ROAs) is critical for protection against BGP prefix hijacks. Recent works quantified ROV enforcing Autonomous Systems (ASes) using control-plane experiments. In this work we show that control-plane experiments do not provide accurate information about ROV-enforcing ASes. We devise data-plane approaches for evaluating ROV in the Internet and perform both control and data-plane experiments using different data acquisition sources. We analyze and correlate the results of our study to identify the number of ASes enforcing ROV, and hence protected with RPKI. We perform simulations with the ROV-enforcing ASes that we identified, and find that their impact on the Internet security against prefix hijacks is negligible. As a countermeasure we provide recommendations how to cope with the main factor hindering wide adoption of ROV.
Tomas Hlavacek, Amir Herzberg, Haya Schulmann, Michael Waidner
DSN1
2018 Perfect is the Enemy of Good: Setting Realistic Goals for BGP Security
abstract
S.57-63
Yossi Gilad, Tomas Hlavacek, Amir Herzberg, Michael Schapira, Haya Schulmann
HotNets2