Niklas Vogel

dblp:332/3113 · DBLP profile ↗
← Back
11ranked-venue papers
0as first author
11since 2021 · last 2026
0009-0004-1461-2419ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 11 since 2021
YearPublicationVenuePosition
2026 Pruning the Tree: Rethinking RPKI Architecture from the Ground up
Haya Schulmann, Niklas Vogel
NDSS2
2026 The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Software
abstract
2815
Oliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel, Michael Waidner
SP4
2026 Batch Me If You Can: Coverage-Guided RPKI Fuzzing at Scale
Haya Schulmann, Niklas Vogel
SP2
2025 Demo: Stopping Production Testing: A Graphical RPKI Test-Suite
abstract
The Resource Public Key Infrastructure (RPKI) is increasingly protecting global BGP routing and major players are pushing for wide-scale adoption. RPKI protection relies on correct publication and validity of RPKI objects: If a prefix has no valid covering RPKI object, e.g., because the object is invalid or expired, the prefix is not protected from hijacks. At the same time, ASes that issue RPKI objects lack any feedback whether their objects are considered valid by all RPKI validation software. This lack of feedback has repeatedly led to operational issues, and problems with object validity are persistent to this day. Oftentimes, issues with objects are only detected in production, after they have caused damage to routing. A prominent example of this is an issue with Amazon objects in 2023 that left 6000 of its prefixes open to hijack in any AS using a specific RPKI validator software implementation. In this work, we present a novel RPKI toolsuite that allows for comprehensive testing of RPKI objects, enabling operators to detect issues in their object configurations before production use. For this, our tool allows parsing arbitrary DER/base64 encoded objects, editing their content and structure, and live-testing them against all current RPKI validator implementations to probe for inconsistent validation results, errors, and even vulnerabilities. Our work provides an important foundation to ensure RPKI resilience against misconfigurations and facilitates future research into RPKI security. We make our tool open-source and provide a hosted web application to enable usage by the community.
Tobias Kirsch, Haya Schulmann, Niklas Vogel
CCS3
2025 Poster: The Rocky Road Towards RPKI Algorithm Agility
abstract
The Resource Public Key Infrastructure (RPKI) already protects around 50% of announced BGP prefixes, and around 28% of systems enforce RPKI validity in routing. RPKI binds ownership of prefixes to public keys inside certificates, which are signed by the respective issuer. For signatures and keys, RPKI currently exclusively supports RSA-2048, forbidding other algorithms and key sizes. In this work, we practically show that RPKI efficiency could significantly benefit from algorithm agility, allowing for smaller more efficient algorithms like Elliptic Curve Cryptography (ECC). We further illustrate that current plans for shifting algorithms, which will eventually become necessary to shift towards quantum-secure algorithms, are infeasible due to bandwidth limitations, validation overhead, and issues with patch management. From our observations, we derive a new agility procedure that uses separate repository versions additional to two separate trees (a mixed tree and a legacy tree) to enable incremental deployment of a new algorithm. In contrast to existing approaches, our procedure provides benefits also for early adopters, facilitating deployment.
Katharina Miesch, Haya Schulmann, Niklas Vogel
CCS3
2025 Poster: We must talk about RPKI Repositories
abstract
The Resource Public Key Infrastructure (RPKI) increasingly protects global routing against attacks. RPKI protection builds on the security and availability of RPKI objects, which are stored in public RPKI repositories. Despite their critical role, not much is known about the technical specifics of these repositories. Which implementations do they use? Is the software maintained and secure? Which vulnerabilities persist? Answering these questions is essential to evaluate security and resilience of current RPKI architecture.
Haya Schulmann, Niklas Vogel
CCS2
2024 The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSEC
abstract
Availability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you send." Hence, nameservers should send not just one matching key for a record set, but all the relevant cryptographic material, e.g., all the keys for all the ciphers that they support and all the corresponding signatures. This ensures that validation succeeds, and hence availability, even if some of the DNSSEC keys are misconfigured, incorrect or correspond to unsupported ciphers.
Elias Heftrig, Haya Schulmann, Niklas Vogel, Michael Waidner
CCS3
2024 Poster: From Fort to Foe: The Threat of RCE in RPKI
abstract
In this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers. We analyze the vulnerability exposing to this RCE and identify indications that the discovered vulnerability could constitute an intentional backdoor to compromise systems running the software over a benign coding mistake. We disclosed the vulnerability, which has been assigned a CVE rated 9.8 critical (CVE-2024-45237).
Oliver Jacobsen, Haya Schulmann, Niklas Vogel, Michael Waidner
CCS3
2024 The CURE to Vulnerabilities in RPKI Validation
Donika Mirdita, Haya Schulmann, Niklas Vogel, Michael Waidner
NDSS3
2023 Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet
Tomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael Waidner
USENIX Security Symposium3
2022 Poster: Insights into Global Deployment of RPKI Validation
abstract
IP prefix hijacks, due to malicious attacks or benign misconfigurations, pose a threat to the Internet's stability and security. RPKI was designed to enable networks to block prefix hijacks by enforcing Route Origin Validation (ROV). In this work we evaluate the effectiveness of the global ROV deployment in blocking prefix hijacks. We perform control-plane and data-plane experiments and provide an in-depth analysis of the collected results. Our analysis is based on new methodologies we developed that allow more accurate identification of ROV enforcing ASes. Our analysis shows that the current ROV enforcement rate is significantly higher than found in previous studies: in contrast to 0.6% in a study from 2021, in our work we find that 37.8% enforce ROV. Our results indicate that ROV has finally gained traction and offers substantial protection against prefix hijacks.
Haya Schulmann, Niklas Vogel, Michael Waidner
CCS2