Donika Mirdita

dblp:248/0549 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0001-6924-4802ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-author · 9 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 All That Glitters is Not Gold: RPKI's Stumbling Speedrun to the Top
abstract
The democratization of access has transformed the Internet into the primary platform for social interaction and economic activity. The COVID-19 pandemic significantly accelerated the digitalization of services, finance and communication. As critical infrastructure increasingly moves online, routing security is becoming a national security concern. U.S. regulatory bodies were the first to sound the alarm by formally recognizing the urgency of Internet routing security and calling for nationwide adoption of security protocols. The Resource Public Key Infrastructure (RPKI) protocol is already the leading standard for protecting Internet routing from hijacking attacks and route leaks. However, RPKI is not secure by design. Research on its security guarantees has shown that despite the minimal public facing interfaces, the software implementations are not only rife with issues, but the nature of these issues is such that they can be easily triggered and disconnect the RPKI security framework from Internet routing, thus severely downgrading RPKI protection benefits. In this work, we evaluate the security properties of RPKI, analyze its attack surface, the required attacker capabilities to launch them, and their consequences on global routing security. We propose that RPKI requires fundamental changes and improvements to mitigate its vulnerabilities, and become robust enough to withstand the eye of the storm.
Donika Mirdita, Haya Schulmann, Michael Waidner
IEEE Trans. Dependable Secur. Comput.1
2025 Poster: Exploring the Landscape of RPKI Relying Parties
abstract
The Resource Public Key Infrastructure (RPKI) is the most successful routing defense mechanism currently deployed throughout critical Internet infrastructures around the world. According to recent works, RPKI deployment boasts over 55% global prefix resource coverage, and at least 27% global protocol enforcement; all this success over a short period of time. In this work, we investigate for the first time deployment trends of the Relying Party (RP), the RPKI component responsible for collecting and enforcing RPKI on routers. We map RP locations, deployment parameters, vulnerability distributions, and describe the evolution of deployment trends over two measurement periods three years apart. Through this exploratory analysis, we map global patterns and the preferred deployment configurations by network operators. We observe how within three years, RP traffic increased by 45%, while 89% of traffic stems from one software type. Our measurements show a strong preference by operators to self-host, coupled with inadequate rates of RP vulnerability mitigation.
Donika Mirdita, Haya Schulmann, Michael Waidner
CCS1
2025 SoK: An Introspective Analysis of RPKI Security
Donika Mirdita, Haya Schulmann, Michael Waidner
USENIX Security Symposium1
2024 Poster: Kill Krill or Proxy RPKI
abstract
Resource Public Key Infrastructure (RPKI), designed to protect Internet routing from hijacks, is gaining traction: over 50% of prefixes have digital certificates, at least 27% of Autonomous Systems actively validate certificates against BGP announcements, and filter invalid routing announcements. In this study, we present the first security analysis of Krill, the only public and open-source RPKI publication point software. Publication points are hosted by the five Regional Internet Registries across the globe, or by independent Internet operators that wish to manage their own RPKI repositories.
Louis Cattepoel, Donika Mirdita, Haya Schulmann, Michael Waidner
CCS2
2024 Byzantine-Secure Relying Party for Resilient RPKI
abstract
BGP is a gaping hole in Internet security, as evidenced by numerous hijacks and outages. The significance of BGP for stability and security of the Internet has made it a top priority on the cyber security agenda of the US government, with CISA, FCC, and other federal agencies leading the efforts.
Jens Frieß, Donika Mirdita, Haya Schulmann, Michael Waidner
CCS2
2024 The CURE to Vulnerabilities in RPKI Validation
Donika Mirdita, Haya Schulmann, Niklas Vogel, Michael Waidner
NDSS1
2023 Beyond Limits: How to Disable Validators in Secure Networks
abstract
Relying party validator is a critical component of RPKI: it fetches and validates signed authorizations mapping prefixes to their owners. Routers use this information to block bogus BGP routes.
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner
SIGCOMM3
2022 Behind the Scenes of RPKI
abstract
Best practices for making RPKI resilient to failures and attacks recommend using multiple URLs and certificates for publication points as well as multiple relying parties. We find that these recommendations are already supported by 63% of the ASes with RPKI.
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner
CCS3
2022 Poster: RPKI Kill Switch
abstract
Relying party implementations are an important component of RPKI: they fetch and validate the signed authorizations mapping prefixes to their owners. Border routers use this information to check which Autonomous Systems (ASes) are authorized to originate given prefixes and to enforce Route Origin Validation (ROV) in order to block bogus BGP announcements, preventing accidental and malicious prefix hijacks. In 2021 the RPKI relying party implementations were patched against attacks by malicious publication points. In such attacks the relying parties are stalled processing malformed RPKI objects. In this work we perform a black-box analysis of the patched relying party implementations and find that out of five popular relying parties, two major implementations (Routinator and OctoRPKI) have vulnerabilities that can be exploited to cause large scale blackouts in the RPKI ecosystem. We show that the vulnerabilities we found apply to 84.9% of the networks supporting RPKI. We analyze the code to understand the factors causing the bugs. We show that these vulnerabilities can be exploited to crash the deployed relying parties, disabling RPKI validation and exposing the networks to prefix hijack attacks.
Donika Mirdita, Haya Schulmann, Michael Waidner
CCS1
2022 Stalloris: RPKI Downgrade Attack
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner
USENIX Security Symposium3