Randy Bush

dblp:81/5952 · DBLP profile ↗
← Back
27ranked-venue papers
2as first author
3since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 22 · 2 first-author · 2 since 2021Security and privacy · 3 · 1 since 2021Systems, architecture and hardware · 2

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
21 papers
Routing and switching · 50% Network measurement and analytics · 22% Software-defined and programmable networks · 9%
Network and information security
5 papers
Network security · 96% Systems and software security · 4%

Topics — the 30 heaviest of 45, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Routing and switching › inter-domain routing
BGP
1.582023
xBGP: Faster Innovation in Routing Protocols · NSDI 2023
BGP Communities: Even more Worms in the Routing Can · Internet Measurement Conference 2018
10 Lessons from 10 Years of Measuring and Modeling the Internet's Autonomous Systems · IEEE J. Sel. Areas Commun. 2011
Routing and switching
inter-domain routing
1.262020
On Measuring RPKI Relying Parties · Internet Measurement Conference 2020
BGP Beacons, Network Tomography, and Bayesian Computation to Locate Route Flap Damping · Internet Measurement Conference 2020
10 Lessons from 10 Years of Measuring and Modeling the Internet's Autonomous Systems · IEEE J. Sel. Areas Commun. 2011
Software-defined and programmable networks
programmable routing
0.712023
xBGP: Faster Innovation in Routing Protocols · NSDI 2023
Routing and switching
routing protocol
0.712023
xBGP: Faster Innovation in Routing Protocols · NSDI 2023
Routing and switching › inter-domain routing › BGP
BGP security
0.632020
On Measuring RPKI Relying Parties · Internet Measurement Conference 2020
iSPY: Detecting IP Prefix Hijacking on My Own · IEEE/ACM Trans. Netw. 2010
Protecting BGP Routes to Top-Level DNS Servers · IEEE Trans. Parallel Distributed Syst. 2003
Network security
routing security
0.642018
BGP Communities: Even more Worms in the Routing Can · Internet Measurement Conference 2018
iSPY: Detecting IP Prefix Hijacking on My Own · IEEE/ACM Trans. Netw. 2010
Ispy: detecting ip prefix hijacking on my own · SIGCOMM 2008
Network measurement and analytics
network tomography
0.412020
BGP Beacons, Network Tomography, and Bayesian Computation to Locate Route Flap Damping · Internet Measurement Conference 2020
Network measurement and analytics › internet measurement
routing measurement
0.412020
On Measuring RPKI Relying Parties · Internet Measurement Conference 2020
Routing and switching › inter-domain routing › inter-domain routing security
RPKI
0.412020
On Measuring RPKI Relying Parties · Internet Measurement Conference 2020
Routing and switching › inter-domain routing › BGP
BGP communities
0.312018
BGP Communities: Even more Worms in the Routing Can · Internet Measurement Conference 2018
Software-defined and programmable networks › SDN threat detection
forwarding anomaly detection
0.312017
Pinpointing delay and forwarding anomalies using large-scale traceroute measurements · Internet Measurement Conference 2017
Network measurement and analytics › active measurement
traceroute measurement
0.312017
Pinpointing delay and forwarding anomalies using large-scale traceroute measurements · Internet Measurement Conference 2017
Network measurement and analytics › internet measurement
deployment measurement
0.212016
A Multi-perspective Analysis of Carrier-Grade NAT Deployment · Internet Measurement Conference 2016
Internet architecture and protocols › middlebox
network address translation
0.212016
A Multi-perspective Analysis of Carrier-Grade NAT Deployment · Internet Measurement Conference 2016
Network measurement and analytics
measurement infrastructure
0.212015
Quantifying Interference between Measurements on the RIPE Atlas Platform · Internet Measurement Conference 2015
Network security › routing security
prefix hijacking detection
0.222010
iSPY: Detecting IP Prefix Hijacking on My Own · IEEE/ACM Trans. Netw. 2010
Ispy: detecting ip prefix hijacking on my own · SIGCOMM 2008
Network measurement and analytics
latency measurement
0.212013
From Paris to Tokyo: on the suitability of ping to measure latency · Internet Measurement Conference 2013
Network performance modeling
network emulation
0.212013
An automated system for emulated network experimentation · CoNEXT 2013
Routing and switching › inter-domain routing › inter-domain routing security › RPKI
route origin validation
0.112020
BGP Beacons, Network Tomography, and Bayesian Computation to Locate Route Flap Damping · Internet Measurement Conference 2020
Network management and operations › network robustness
routing robustness
0.112020
On Measuring RPKI Relying Parties · Internet Measurement Conference 2020
Internet architecture and protocols › network topology
inter-domain topology
0.112011
10 Lessons from 10 Years of Measuring and Modeling the Internet's Autonomous Systems · IEEE J. Sel. Areas Commun. 2011
Network measurement and analytics
internet topology measurement
0.112011
10 Lessons from 10 Years of Measuring and Modeling the Internet's Autonomous Systems · IEEE J. Sel. Areas Commun. 2011
Routing and switching › inter-domain routing › BGP
BGP churn
0.112010
Evolution of Internet Address Space Deaggregation: Myths and Reality · IEEE J. Sel. Areas Commun. 2010
Routing and switching › inter-domain routing
routing table growth
0.112010
Evolution of Internet Address Space Deaggregation: Myths and Reality · IEEE J. Sel. Areas Commun. 2010
Network management and operations
configuration management
0.112009
Configuration management and security · IEEE J. Sel. Areas Commun. 2009
Routing and switching
routing
0.112009
Internet optometry: assessing the broken glasses in internet reachability · Internet Measurement Conference 2009
Network management and operations › network configuration
security configuration
0.112009
Configuration management and security · IEEE J. Sel. Areas Commun. 2009
Network management and operations › fault management
fault diagnosis
0.112008
Ispy: detecting ip prefix hijacking on my own · SIGCOMM 2008
Network measurement and analytics › internet measurement › routing measurement
routing dynamics measurement
0.112006
A measurement study on the impact of routing events on end-to-end internet path performance · SIGCOMM 2006
Network measurement and analytics › network performance measurement
internet performance monitoring
0.012013
From Paris to Tokyo: on the suitability of ping to measure latency · Internet Measurement Conference 2013

Methods — techniques the papers use, named apart from their topics

active probing · 0.4network tomography · 0.4longitudinal measurement · 0.4bayesian computation · 0.4BGP beacons · 0.4traceroute analysis · 0.3packet forwarding model · 0.3alarm scoring · 0.3multi-perspective measurement · 0.2empirical measurement · 0.2reachability monitoring · 0.1simulation · 0.1path-filtering · 0.0heuristics · 0.0
YearPublicationVenuePosition
2024 The Resource Public Key Infrastructure (RPKI): A Survey on Measurements and Future Prospects
abstract
The adoption of the Resource Public Key Infrastructure (RPKI) is increasing. To better understand and improve RPKI deployment, measuring route origin authorization (ROA) objects, RPKI route origin validation (ROV), and RPKI resilience is essential. In this paper, we survey RPKI-related research that aims to understand RPKI deployment. Additionally, we enrich our survey with many industry and IETF-related contributions. Our work provides an in-depth analysis of the many ideas and challenges discussed in studies of the RPKI ecosystem and includes lessons from mistakes made in the past, which we should avoid in the future.
Nils Rodday, Ítalo S. Cunha, Randy Bush, Ethan Katz-Bassett, Gabi Dreo Rodosek, Thomas C. Schmidt, Matthias Wählisch
IEEE Trans. Netw. Serv. Manag.3
2023 xBGP: Faster Innovation in Routing Protocols
Thomas Wirtgen, Tom Rousseaux, Quentin De Coninck, Nicolas Rybowski, Randy Bush, Laurent Vanbever, Axel Legay, Olivier Bonaventure
NSDI5
2023 RPKI Time-of-Flight: Tracking Delays in the Management, Control, and Data Planes
Romain Fontugne, Amreesh Phokeer, Cristel Pelsser, Kevin Vermeulen, Randy Bush
PAM5
2020 xBGP: When You Can't Wait for the IETF and Vendors
abstract
Thanks to the standardization of routing protocols such as BGP, OSPF or IS-IS, Internet Service Providers (ISP) and enterprise networks can deploy routers from various vendors. This prevents them from vendor-lockin problems. Unfortunately, this also slows innovation since any new feature must be standardized and implemented by all vendors before being deployed.
Thomas Wirtgen, Quentin De Coninck, Randy Bush, Laurent Vanbever, Olivier Bonaventure
HotNets3
2020 BGP Beacons, Network Tomography, and Bayesian Computation to Locate Route Flap Damping
abstract
Pinpointing autonomous systems which deploy specific inter-domain techniques such as Route Flap Damping (RFD) or Route Origin Validation (ROV) remains a challenge today. Previous approaches to detect per-AS behavior often relied on heuristics derived from passive and active measurements. Those heuristics, however, often lacked accuracy or imposed tight restrictions on the measurement methods.
Caitlin Gray, Clemens Mosig, Randy Bush, Cristel Pelsser, Matthew Roughan, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference3
2020 On Measuring RPKI Relying Parties
abstract
In this paper, we introduce a framework to observe RPKI relying parties (i.e., those that fetch RPKI data from the distributed repository) and present insights into this ecosystem for the first time. Our longitudinal study of data gathered from three RPKI certification authorities (AFRINIC, APNIC, and our own CA) identifies different deployment models of relying parties and (surprisingly) prevalent inconsistent fetching behavior that affects Internet routing robustness. Our results reveal nearly 90% of relying parties are unable to connect to delegated publication points under certain conditions, which leads to erroneous invalidation of IP prefixes and likely widespread loss of network reachability.
John Kristoff, Randy Bush, Chris Kanich, George Michaelson, Amreesh Phokeer, Thomas C. Schmidt, Matthias Wählisch
Internet Measurement Conference2
2018 BGP Communities: Even more Worms in the Routing Can
Florian Streibelt, Franziska Lichtblau, Robert Beverly, Anja Feldmann, Cristel Pelsser, Georgios Smaragdakis, Randy Bush
Internet Measurement Conference7
2017 Pinpointing delay and forwarding anomalies using large-scale traceroute measurements
abstract
Understanding data plane health is essential to improving Internet reliability and usability. For instance, detecting disruptions in distant networks can identify repairable connectivity problems. Currently this task is difficult and time consuming as operators have poor visibility beyond their network's border. In this paper we leverage the diversity of RIPE Atlas traceroute measurements to solve the classic problem of monitoring in-network delays and get credible delay change estimations to monitor network conditions in the wild. We demonstrate a set of complementary methods to detect network disruptions and report them in near real time. The first method detects delay changes for intermediate links in traceroutes. Second, a packet forwarding model predicts traffic paths and identifies faulty routers and links in cases of packet loss. In addition, we define an alarm score that aggregates changes into a single value per AS in order to easily monitor its sanity, reducing the effect of uninteresting alarms. Using only existing public data we monitor hundreds of thousands of link delays while adding no burden to the network. We present three cases demonstrating that the proposed methods detect real disruptions and provide valuable insights, as well as surprising findings, on the location and impact of the identified events.
Romain Fontugne, Cristel Pelsser, Emile Aben, Randy Bush
Internet Measurement Conference4
2016 A Multi-perspective Analysis of Carrier-Grade NAT Deployment
Philipp Richter, Florian Wohlfart, Narseo Vallina-Rodriguez, Mark Allman, Randy Bush, Anja Feldmann, Christian Kreibich, Nicholas Weaver, Vern Paxson
Internet Measurement Conference5
2015 Quantifying Interference between Measurements on the RIPE Atlas Platform
abstract
Public measurement platforms composed of low-end hardware devices such as RIPE Atlas have gained significant traction in the research community. Such platforms are indeed particularly interesting as they provide Internet-wide measurement capabilities together with an ever growing set of measurement tools. To be scalable though, they allow for concurrent measurements between users. This paper answers a fundamental question for any platform user: Do measurements launched by others impact my results? If so, what can I do about it?
Thomas Holterbach, Cristel Pelsser, Randy Bush, Laurent Vanbever
Internet Measurement Conference3
2015 Measuring BGP Route Origin Registration and Validation
Daniele Iamartino, Cristel Pelsser, Randy Bush
PAM3
2014 IPv4 Address Sharing Mechanism Classification and Tradeoff Analysis
abstract
The growth of the Internet has made IPv4 addresses a scarce resource. Due to slow IPv6 deployment, IANA-level IPv4 address exhaustion was reached before the world could transition to an IPv6-only Internet. The continuing need for IPv4 reachability will only be supported by IPv4 address sharing. This paper reviews ISP-level address sharing mechanisms, which allow Internet service providers to connect multiple customers who share a single IPv4 address. Some mechanisms come with severe and unpredicted consequences, and all of them come with tradeoffs. We propose a novel classification, which we apply to existing mechanisms such as NAT444 and DS-Lite and proposals such as 4rd, MAP, etc. Our tradeoff analysis reveals insights into many problems including: abuse attribution, performance degradation, address and port usage efficiency, direct intercustomer communication, and availability.
Nejc Skoberne, Olaf Maennel, Iain Phillips 0002, Randy Bush, Jan Zorz, Mojca Ciglaric
IEEE/ACM Trans. Netw.4
2013 An automated system for emulated network experimentation
abstract
Emulated networks and systems, where router and server software are run in virtual environments, allow network operators and researchers to perform experiments at large scale more economically than in testbeds. Running real code provides a greater level of realism than simulation.
Simon Knight 0002, Hung X. Nguyen, Olaf Maennel, Iain Phillips 0002, Nick Falkner, Randy Bush, Matthew Roughan
CoNEXT6
2013 From Paris to Tokyo: on the suitability of ping to measure latency
abstract
Monitoring Internet performance and measuring user quality of experience are drawing increased attention from both research and industry. To match this interest, large-scale measurement infrastructures have been constructed. We believe that this effort must be combined with a critical review and calibrarion of the tools being used to measure performance.
Cristel Pelsser, Luca Cittadini, Stefano Vissicchio, Randy Bush
Internet Measurement Conference4
2011 Route Flap Damping Made Usable
Cristel Pelsser, Olaf Maennel, Pradosh Mohapatra, Randy Bush, Keyur Patel
PAM4
2011 10 Lessons from 10 Years of Measuring and Modeling the Internet's Autonomous Systems
abstract
Formally, the Internet inter-domain routing system is a collection of networks, their policies, peering relationships and organizational affiliations, and the addresses they advertize. It also includes components like Internet exchange points. By its very definition, each and every aspect of this system is impacted by BGP, the de-facto standard inter-domain routing protocol. The element of this inter-domain routing system that has attracted the single-most attention within the research community has been the "inter-domain topology". Unfortunately, almost from the get go, the vast majority of studies of this topology, from definition, to measurement, to modeling and analysis, have ignored the central role of BGP in this problem. The legacy is a set of specious findings, unsubstantiated claims, and ill-conceived ideas about the Internet as a whole. By presenting a BGP-focused state-of-the-art treatment of the aspects that are critical for a rigorous study of this inter-domain topology, we demystify in this paper many "controversial" observations reported in the existing literature. At the same time, we illustrate the benefits and richness of new scientific approaches to measuring, modeling, and analyzing the inter-domain topology that are faithful to the BGP-specific nature of this problem domain.
Matthew Roughan, Walter Willinger, Olaf Maennel, Debbie Perouli, Randy Bush
IEEE J. Sel. Areas Commun.5
2010 Evolution of Internet Address Space Deaggregation: Myths and Reality
abstract
Internet routing table size growth and BGP update churn are two prominent Internet scaling issues. There is widespread belief in a high and fast growing number of ASs that deaggregate prefixes, e.g., due to multi-homing and for the purpose of traffic engineering. Moreover, researchers often blame specific classes of ASs for generating a disproportionate amount of BGP updates. Our primary objective is to challenge such widespread assumptions (“myths”) and not solely to confirm previous findings. Surprisingly, we find severe discrepancies between existing myths and reality. According to our results, there is no trend towards more aggressive prefix deaggregation or traffic engineering over time. With respect to update dynamics, we observe that deaggregated prefixes generally do not generate a disproportionate number of BGP updates, with respect to their share of the BGP routing table. On the other side, we observe much more widespread traffic engineering in the form of AS path prepending and scoped advertisements compared to previous studies. Overall, our work gives a far more positive picture compared to the alarming discourses typically heard: The impact of “bad guys” on routing table size growth and BGP churn has not changed for the worse in recent years. Rather, it increases at the same pace as the Internet itself.
Luca Cittadini, Wolfgang Mühlbauer, Steve Uhlig, Randy Bush, Pierre François, Olaf Maennel
IEEE J. Sel. Areas Commun.4
2010 iSPY: Detecting IP Prefix Hijacking on My Own
abstract
IP prefix hijacking remains a major threat to the security of the Internet routing system due to a lack of authoritative prefix ownership information. Despite many efforts in designing IP prefix hijack detection schemes, no existing design can satisfy all the critical requirements of a truly effective system: real-time, accurate, lightweight, easily and incrementally deployable, as well as robust in victim notification. In this paper, we present a novel approach that fulfills all these goals by monitoring network reachability from key external transit networks to one's own network through lightweight prefix-owner-based active probing. Using the prefix-owner's view of reachability, our detection system, iSPY, can differentiate between IP prefix hijacking and network failures based on the observation that hijacking is likely to result in topologically more diverse polluted networks and unreachability. Through detailed simulations of Internet routing, 25-day deployment in 88 autonomous systems (ASs) (108 prefixes), and experiments with hijacking events of our own prefix from multiple locations, we demonstrate that iSPY is accurate with false negative ratio below 0.45% and false positive ratio below 0.17%. Furthermore, iSPY is truly real-time; it can detect hijacking events within a few minutes.
Zheng Zhang 0009, Ying Zhang 0022, Y. Charlie Hu, Z. Morley Mao, Randy Bush
IEEE/ACM Trans. Netw.5
2009 Internet optometry: assessing the broken glasses in internet reachability
abstract
Reachability is thought of as the most basic service provided by today's Internet. Unfortunately, this does not imply that the community has a deep understanding of it. Researchers and operators rely on two views of reachability: control/routing- and data-plane measurements, but both types of measurements suffer from biases and limitations. In this paper, we illustrate some of these biases, and show how to design controlled experiments which allow us to "see" through the limitations of previous measurement techniques. For example, we discover the extent of default routing and its impact on reachability. This explains some of the previous unexpected results from studies that compared control- and data-plane measurements.
Randy Bush, Olaf Maennel, Matthew Roughan, Steve Uhlig
Internet Measurement Conference1
2009 Configuration management and security
abstract
Proper configuration management is vital for host and network security. We outline the problems, especially for large-scale environments, and discuss the security aspects of a number of different configuration scenarios, including security appliances (e.g., firewalls), desktop and server computers, and PDAs. We conclude by discussing research challenges.
Steven M. Bellovin, Randy Bush
IEEE J. Sel. Areas Commun.2
2008 Ispy: detecting ip prefix hijacking on my own
abstract
IP prefix hijacking remains a major threat to the security of the Internet routing system due to a lack of authoritative prefix ownership information. Despite many efforts in designing IP prefix hijack detection schemes, no existing design can satisfy all the critical requirements of a truly effective system: real-time, accurate, light-weight, easily and incrementally deployable, as well as robust in victim notification. In this paper, we present a novel approach that fulfills all these goals by monitoring network reachability from key external transit networks to one's own network through lightweight prefix-owner-based active probing. Using the prefix-owner's view of reachability, our detection system, iSPY, can differentiate between IP prefix hijacking and network failures based on the observation that hijacking is likely to result in topologically more diverse polluted networks and unreachability. Through detailed simulations of Internet routing, 25-day deployment in 88 ASes (108 prefixes), and experiments with hijacking events of our own prefix from multiple locations, we demonstrate that iSPY is accurate with false negative ratio below 0.45% and false positive ratio below 0.17%. Furthermore, iSPY is truly real-time; it can detect hijacking events within a few minutes.
Zheng Zhang 0009, Ying Zhang 0022, Y. Charlie Hu, Z. Morley Mao, Randy Bush
SIGCOMM5
2006 A measurement study on the impact of routing events on end-to-end internet path performance
abstract
Extensive measurement studies have shown that end-to-end Internet path performance degradation is correlated with routing dynamics. However, the root cause of the correlation between routing dynamics and such performance degradation is poorly understood. In particular, how do routing changes result in degraded end-to-end path performance in the first place? How do factors such as topological properties, routing policies, and iBGP configurations affect the extent to which such routing events can cause performance degradation? Answers to these questions are critical for improving network performance.In this paper, we conduct extensive measurement that involves both controlled routing updates through two tier-1 ISPs and active probes of a diverse set of end-to-end paths on the Internet. We find that routing changes contribute to end-to-end packet loss significantly. Specifically, we study failover events in which a link failure leads to a routing change and recovery events in which a link repair causes a routing change. In both cases, it is possible to experience data plane performance degradation in terms of increased long loss burst as well as forwarding loops. Furthermore, we find that common routing policies and iBGP configurations of ISPs can directly affect the end-to-end path performance during routing changes. Our work provides new insights into potential measures that network operators can undertake to enhance network performance.
Feng Wang 0017, Z. Morley Mao, Jia Wang 0001, Lixin Gao 0001, Randy Bush
SIGCOMM5
2003 Protecting BGP Routes to Top Level DNS Servers
abstract
The Domain Name System (DNS) is an essential part of the Internet infrastructure and provides fundamental services, such as translating host names into IP addresses for Internet communication. The DNS is vulnerable to a number of potential faults and attacks. In particular, false routing announcements can deny access to the DNS service or redirect DNS queries to a malicious impostor Due to the hierarchical DNS design, a single fault or attack against the routes to any of the top level DNS servers can disrupt Internet services to millions of users. In this paper we propose a path-filtering approach to protect the routes to the critical top level DNS servers. Our approach exploits the high degree of redundancy in top level DNS servers and also exploits the observation that popular destinations, including top level DNS servers, are well connected via stable routes. Our path-filter restricts the potential top level DNS server route changes to be within a set of established paths. Heuristics derived from routing operations are used to adjust the potential routes overtime. We tested our path-filtering design against BGP routing logs and the results show that the design can effectively ensure correct routes to top level DNS servers without impacting DNS service availability.
Xiaoliang Zhao, Dan Pei, Randy Bush, Daniel Massey, Allison Mankin, Shyhtsun Felix Wu, Lixia Zhang 0001
ICDCS4
2003 BGP beacons
abstract
The desire to better understand global BGP dynamics has motivated several studies using active measurement techniques, which inject announcements and withdrawals of prefixes from the global routing domain. From these one can measure quantities such as the BGP convergence time. Previously, the route injection infrastructure of such experiments has either been temporary in nature, or its use has been restricted to the experimenters. The routing research community would benefit from a permanent and public infrastructure for such active probes. We use the term BGP Beacon to refer to a publicly documented prefix having global visibility and a published schedule for announcements and withdrawals. A BGP Beacon is to be used for the ongoing study of BGP dynamics, and so should be supportedwith a long-term commitment. We describe several BGP Beacons thathave been set up at various points in the Internet. We then describe techniques for processing BGP updates when a BGP Beacon is observed from a BGP monitoring point such as Oregon's Route Views. Finally, we illustrate the use of BGP Beacons in the analysis of convergence delays, route flap damping, and update inter-arrival times.
Z. Morley Mao, Randy Bush, Timothy G. Griffin, Matthew Roughan
Internet Measurement Conference2
2003 Integrity for Virtual Private Routed Networks
abstract
The term virtual private network (VPN) encompasses a wide array of diverse technologies and network architectures. All VPNs should provide users with the isolation and security associated with private networks, but at lower costs made possible by implementing these networks over some type of shared infrastructure. Provider provisioned VPN allow enterprises to outsource their private backbone networks to service providers. For this reason, we will also refer to them as virtual private routed networks (VPRNs). This contrasts with other VPN technologies that require customers to manage their own point-to-point connections (leased lines or tunnels) and associated network administration. One type of VPRN currently being deployed is described in RFC 2547, which uses BGP to propagate routing information for all VPNs implemented within a provider's backbone, and a tunneling technology, such as MPLS, to isolate traffic. This technology requires fairly complex configurations within the backbone, and so poses challenges to providers supporting a large number of VPN customers. We present a formal analysis of several configuration and implementation concerns for VPRNs of the RFC 2547 variety. In particular, we focus on integrity constraints that must be maintained by providers in order to ensure that intraVPRN connectivity is achieved, and that disjoint VPRNs are isolated from each other.
Randy Bush, Timothy G. Griffin
INFOCOM1
2003 Protecting BGP Routes to Top-Level DNS Servers
abstract
The Domain Name System (DNS) is an essential part of the Internet infrastructure and provides fundamental services, such as translating host names into IP addresses for Internet communication. The DNS is vulnerable to a number of potential faults and attacks. In particular, false routing announcements can deny access to the DNS service or redirect DNS queries to a malicious impostor. Due to the hierarchical DNS design, a single fault or attack against the routes to any of the top-level DNS servers can disrupt Internet services to millions of users. We propose a path-filtering approach to protect the routes to the critical top-level DNS servers. Our approach exploits both the high degree of redundancy in top-level DNS servers and the observation that popular destinations, including top-level DNS servers, are well-connected via stable routes. Our path-filter restricts the potential top-level DNS server route changes to be within a set of established paths. Heuristics derived from routing operations are used to adjust the potential routes over time. We tested our path-filtering design against BGP routing logs and the results show that the design can effectively ensure correct routes to top-level DNS servers without impacting DNS service availability.
Xiaoliang Zhao, Dan Pei, Randy Bush, Daniel Massey, Lixia Zhang 0001
IEEE Trans. Parallel Distributed Syst.4
2002 Observation and analysis of BGP behavior under stress
abstract
Despite BGP's critical importance as the de-facto Internet inter-domain routing protocol, there is little understanding of how BGP actually performs under stressful conditions when dependable routing is most needed. In this paper, we examine BGP's behavior during one stressful period, the Code Red/Nimda attack on September 18, 2001. The attack was correlated with a 30-fold increase in the BGP update messages at a monitoring point which peers with a number of Internet service providers. Our examination of BGP's behavior during the event concludes that BGP exhibited no significant abnormality, and that over 40% of the observed updates can be attributed to the monitoring artifact in current BGP measurement settings. Our analysis, however, does reveal several weak points in both the protocol and its implementation, such as BGP's sensitivity to the transport session reliability, its inability to avoid the global propagation of small local changes, and its certain implementation features whose otherwise benign effects only get amplified under stressful conditions. We also identify areas for improvement in the current network measurement and monitoring effort.
Xiaoliang Zhao, Dan Pei, Randy Bush, Daniel Massey, Allison Mankin, Shyhtsun Felix Wu, Lixia Zhang 0001
Internet Measurement Workshop4