狠狠撸

狠狠撸Share a Scribd company logo
Internet Routing Security
Kenny Huang, Ph.D.
CEO, Director of the board, TWNIC
huangk@twnic.net.tw
2018 Feb. 07
黃勝雄博士
Circuit switching vs. packet switching
2
Forwarding decision ?
●
●
3
ARPANet 1969
4
Dynamic routing protocols
5
●
●
●
●
Internet Protocol
6
IGP - Distance Vector
●
●
●
7
IGP - link state
●
●
8
Growth of Internet routing table
9
EGP
●
●
10
EGP
11
BGP - IETF12 (1989)
●
●
12
BGP
13
●
●
Internet routing security - detour
14
BGP routing
15
China telecom hijacks verizon wireless
16
Pakistan telecom hijacks youtube
17
Moratel leaks a route to pccw
18
19
●
○
2017 Routing security
2017 Routing security
20
●
○
●
○
○
○
○
○
○
2017 Routing security
●
○
○
●
○
●
○
21
22
●
●
23
24
25
26
Trust for Internet Interconnection
27
●
○
○
●
○
○
○
●
○
○
Trust and distrust dual-stack model
●
○
○
●
○
○
○
28
Current practice for interconnection relationship
●
●
○
○
○
○
29
Coping with distrust
●
○
●
○
○
●
○
30
The value of distrust
●
○
●
○
○
○
31
32
Internet governance and cybersecurity
33
Code is law
34
Secure namespace - dnssec
35
Secured Communication
36
Evolution of Cybersecurity Strategy
37
Internet Routing Registry
●
○
○
●
○
○
38
Commercial Routing registry database
●
○
○
●
○
○
39
RPSL
●
○
●
○
40
Fragmentation within RPSL
●
○
○
● …
○
○
○
●
○
○
○
41
APNIC Internet Routing Registry (WHOIS)
●
○
●
○
●
○
○
42
Benefit of APNIC WHOIS
●
●
○
●
○
○
○
43
What is RPKI
●
●
●
44
Who
●
○
●
○
○
●
○
45
When
46
●
○
○
●
○
Where
47
Why
48
●
○
○
●
○
●
○
■
How
●
○
■
■
●
○
○
○
49
How much
●
○
●
○
●
○
50
ROA Content
●
○
○
●
○
○
○
○
51
What it look like
52
53
Coverage for RPKI and RPSL
●
●
●
54
RPKI deployment status
55
Challenge to Deployment
56
Three Route States
●
○
●
○
●
○
■
■
■
57
What to do with this data now
●
●
○
○
○
●
●
58
Public Resources
59
Secure internet routing - RPKI
60
Problem solved
61
When
●
○
○
○
62
BGPsec - RFC8205
63
BGPsec
64
What does BGPsec offer over RPKI
65
●
●
66
Ad

Recommended

DEF CON 27- JACOB BAINES - help me vulnerabilities - you are my only hope
DEF CON 27- JACOB BAINES - help me vulnerabilities - you are my only hope
Felipe Prado
?
Running BGP with Mikrotik
Running BGP with Mikrotik
GLC Networks
?
Best Current Practice (BCP) 38 Ingress Filtering for Security
Best Current Practice (BCP) 38 Ingress Filtering for Security
GLC Networks
?
CCNA : Intro to Cisco IOS - Part 1
CCNA : Intro to Cisco IOS - Part 1
GLC Networks
?
Blockchain in Telecom: Practical Cases
Blockchain in Telecom: Practical Cases
PortaOne
?
Mikrotik IP Settings For Performance and Security
Mikrotik IP Settings For Performance and Security
GLC Networks
?
6G Training Course Part 2: 6G Vision
6G Training Course Part 2: 6G Vision
3G4G
?
贬补辞冲蚕颈苍冲笔谤别蝉别苍迟补迟颈辞苍-秦博士.辫诲蹿
贬补辞冲蚕颈苍冲笔谤别蝉别苍迟补迟颈辞苍-秦博士.辫诲蹿
lstclstc
?
Internet Protocol Deep-Dive
Internet Protocol Deep-Dive
GLC Networks
?
Firewall mangle PBR: steering outbound path similar to inbound
Firewall mangle PBR: steering outbound path similar to inbound
GLC Networks
?
CE1009_Implementation of Civil IoT Architecture.pdf
CE1009_Implementation of Civil IoT Architecture.pdf
Chenkai Sun
?
Build Your Own ISP
Build Your Own ISP
GLC Networks
?
MTCNA Intro to routerOS
MTCNA Intro to routerOS
GLC Networks
?
Advanced: Private Networks & 5G Non-Public Networks
Advanced: Private Networks & 5G Non-Public Networks
3G4G
?
BGP Services IP Transit vs IP Peering
BGP Services IP Transit vs IP Peering
GLC Networks
?
RouterOS Migration From v6 to v7
RouterOS Migration From v6 to v7
GLC Networks
?
Voice Services, From Circuit Switch to VoIP
Voice Services, From Circuit Switch to VoIP
GLC Networks
?
MTCNA : Intro to RouterOS - Part 1
MTCNA : Intro to RouterOS - Part 1
GLC Networks
?
Ieee 2018 2019 project titiles
Ieee 2018 2019 project titiles
Finalyearprojects Toall
?
Networking in Telecommunication (signalling, tcp, ucp, ss7, sctp, sigtran)
Networking in Telecommunication (signalling, tcp, ucp, ss7, sctp, sigtran)
GLC Networks
?
Building Local-loop Services for Customers
Building Local-loop Services for Customers
GLC Networks
?
Zabbix for Monitoring
Zabbix for Monitoring
GLC Networks
?
EOIP Deep Dive
EOIP Deep Dive
GLC Networks
?
BGP on mikrotik
BGP on mikrotik
Achmad Mardiansyah
?
Controlling Access Between Devices in the same Layer 2 Segment
Controlling Access Between Devices in the same Layer 2 Segment
GLC Networks
?
IPv6 with Mikrotik
IPv6 with Mikrotik
GLC Networks
?
Mikrotik firewall filter
Mikrotik firewall filter
Achmad Mardiansyah
?
Mikrotik Hotspot
Mikrotik Hotspot
GLC Networks
?
Taiwan Internet Intermediaries and Cyber Norms
Taiwan Internet Intermediaries and Cyber Norms
Kenny Huang Ph.D.
?
Internet Governance Model in Taiwan
Internet Governance Model in Taiwan
Kenny Huang Ph.D.
?

More Related Content

Similar to Internet Routing Security (20)

Internet Protocol Deep-Dive
Internet Protocol Deep-Dive
GLC Networks
?
Firewall mangle PBR: steering outbound path similar to inbound
Firewall mangle PBR: steering outbound path similar to inbound
GLC Networks
?
CE1009_Implementation of Civil IoT Architecture.pdf
CE1009_Implementation of Civil IoT Architecture.pdf
Chenkai Sun
?
Build Your Own ISP
Build Your Own ISP
GLC Networks
?
MTCNA Intro to routerOS
MTCNA Intro to routerOS
GLC Networks
?
Advanced: Private Networks & 5G Non-Public Networks
Advanced: Private Networks & 5G Non-Public Networks
3G4G
?
BGP Services IP Transit vs IP Peering
BGP Services IP Transit vs IP Peering
GLC Networks
?
RouterOS Migration From v6 to v7
RouterOS Migration From v6 to v7
GLC Networks
?
Voice Services, From Circuit Switch to VoIP
Voice Services, From Circuit Switch to VoIP
GLC Networks
?
MTCNA : Intro to RouterOS - Part 1
MTCNA : Intro to RouterOS - Part 1
GLC Networks
?
Ieee 2018 2019 project titiles
Ieee 2018 2019 project titiles
Finalyearprojects Toall
?
Networking in Telecommunication (signalling, tcp, ucp, ss7, sctp, sigtran)
Networking in Telecommunication (signalling, tcp, ucp, ss7, sctp, sigtran)
GLC Networks
?
Building Local-loop Services for Customers
Building Local-loop Services for Customers
GLC Networks
?
Zabbix for Monitoring
Zabbix for Monitoring
GLC Networks
?
EOIP Deep Dive
EOIP Deep Dive
GLC Networks
?
BGP on mikrotik
BGP on mikrotik
Achmad Mardiansyah
?
Controlling Access Between Devices in the same Layer 2 Segment
Controlling Access Between Devices in the same Layer 2 Segment
GLC Networks
?
IPv6 with Mikrotik
IPv6 with Mikrotik
GLC Networks
?
Mikrotik firewall filter
Mikrotik firewall filter
Achmad Mardiansyah
?
Mikrotik Hotspot
Mikrotik Hotspot
GLC Networks
?
Internet Protocol Deep-Dive
Internet Protocol Deep-Dive
GLC Networks
?
Firewall mangle PBR: steering outbound path similar to inbound
Firewall mangle PBR: steering outbound path similar to inbound
GLC Networks
?
CE1009_Implementation of Civil IoT Architecture.pdf
CE1009_Implementation of Civil IoT Architecture.pdf
Chenkai Sun
?
MTCNA Intro to routerOS
MTCNA Intro to routerOS
GLC Networks
?
Advanced: Private Networks & 5G Non-Public Networks
Advanced: Private Networks & 5G Non-Public Networks
3G4G
?
BGP Services IP Transit vs IP Peering
BGP Services IP Transit vs IP Peering
GLC Networks
?
RouterOS Migration From v6 to v7
RouterOS Migration From v6 to v7
GLC Networks
?
Voice Services, From Circuit Switch to VoIP
Voice Services, From Circuit Switch to VoIP
GLC Networks
?
MTCNA : Intro to RouterOS - Part 1
MTCNA : Intro to RouterOS - Part 1
GLC Networks
?
Networking in Telecommunication (signalling, tcp, ucp, ss7, sctp, sigtran)
Networking in Telecommunication (signalling, tcp, ucp, ss7, sctp, sigtran)
GLC Networks
?
Building Local-loop Services for Customers
Building Local-loop Services for Customers
GLC Networks
?
Zabbix for Monitoring
Zabbix for Monitoring
GLC Networks
?
Controlling Access Between Devices in the same Layer 2 Segment
Controlling Access Between Devices in the same Layer 2 Segment
GLC Networks
?

More from Kenny Huang Ph.D. (20)

Taiwan Internet Intermediaries and Cyber Norms
Taiwan Internet Intermediaries and Cyber Norms
Kenny Huang Ph.D.
?
Internet Governance Model in Taiwan
Internet Governance Model in Taiwan
Kenny Huang Ph.D.
?
Cyberspace and Digital Diplomacy
Cyberspace and Digital Diplomacy
Kenny Huang Ph.D.
?
网路治理概念、组织及案例
网路治理概念、组织及案例
Kenny Huang Ph.D.
?
Ethical Considerations in AI
Ethical Considerations in AI
Kenny Huang Ph.D.
?
创新网路服务产业发展条例建议草案
创新网路服务产业发展条例建议草案
Kenny Huang Ph.D.
?
APNIC44 Briefing
APNIC44 Briefing
Kenny Huang Ph.D.
?
共享经济关键议题之探讨
共享经济关键议题之探讨
Kenny Huang Ph.D.
?
Cybersecurity and Internet Governance
Cybersecurity and Internet Governance
Kenny Huang Ph.D.
?
网路中立性介绍
网路中立性介绍
Kenny Huang Ph.D.
?
谈已发展与发展中国家数位落差
谈已发展与发展中国家数位落差
Kenny Huang Ph.D.
?
Spectrum Policy
Spectrum Policy
Kenny Huang Ph.D.
?
IoT Security and Privacy Considerations
IoT Security and Privacy Considerations
Kenny Huang Ph.D.
?
Smart Energy
Smart Energy
Kenny Huang Ph.D.
?
Smart Vehicle and Data Service Provisioning
Smart Vehicle and Data Service Provisioning
Kenny Huang Ph.D.
?
物联网与工业4.0情境分析
物联网与工业4.0情境分析
Kenny Huang Ph.D.
?
Cloud Computing Business Models Review
Cloud Computing Business Models Review
Kenny Huang Ph.D.
?
Democracy 3.0 Experiences From Taiwan; Internet Empowerment in Taiwan Sunflow...
Democracy 3.0 Experiences From Taiwan; Internet Empowerment in Taiwan Sunflow...
Kenny Huang Ph.D.
?
Big Data : Risks and Opportunities
Big Data : Risks and Opportunities
Kenny Huang Ph.D.
?
Taiwan Network Environment Analysis
Taiwan Network Environment Analysis
Kenny Huang Ph.D.
?
Taiwan Internet Intermediaries and Cyber Norms
Taiwan Internet Intermediaries and Cyber Norms
Kenny Huang Ph.D.
?
Internet Governance Model in Taiwan
Internet Governance Model in Taiwan
Kenny Huang Ph.D.
?
Cyberspace and Digital Diplomacy
Cyberspace and Digital Diplomacy
Kenny Huang Ph.D.
?
网路治理概念、组织及案例
网路治理概念、组织及案例
Kenny Huang Ph.D.
?
创新网路服务产业发展条例建议草案
创新网路服务产业发展条例建议草案
Kenny Huang Ph.D.
?
共享经济关键议题之探讨
共享经济关键议题之探讨
Kenny Huang Ph.D.
?
Cybersecurity and Internet Governance
Cybersecurity and Internet Governance
Kenny Huang Ph.D.
?
谈已发展与发展中国家数位落差
谈已发展与发展中国家数位落差
Kenny Huang Ph.D.
?
IoT Security and Privacy Considerations
IoT Security and Privacy Considerations
Kenny Huang Ph.D.
?
Smart Vehicle and Data Service Provisioning
Smart Vehicle and Data Service Provisioning
Kenny Huang Ph.D.
?
物联网与工业4.0情境分析
物联网与工业4.0情境分析
Kenny Huang Ph.D.
?
Cloud Computing Business Models Review
Cloud Computing Business Models Review
Kenny Huang Ph.D.
?
Democracy 3.0 Experiences From Taiwan; Internet Empowerment in Taiwan Sunflow...
Democracy 3.0 Experiences From Taiwan; Internet Empowerment in Taiwan Sunflow...
Kenny Huang Ph.D.
?
Big Data : Risks and Opportunities
Big Data : Risks and Opportunities
Kenny Huang Ph.D.
?
Taiwan Network Environment Analysis
Taiwan Network Environment Analysis
Kenny Huang Ph.D.
?
Ad

Recently uploaded (20)

Lecture 3.1 Analysing the Global Business Environment .pptx
Lecture 3.1 Analysing the Global Business Environment .pptx
shofalbsb
?
狠狠撸s: Eco Economic Epochs for The World Game (s) pdf
狠狠撸s: Eco Economic Epochs for The World Game (s) pdf
Steven McGee
?
最新版美国特拉华大学毕业证(鲍顿别濒毕业证书)原版定制
最新版美国特拉华大学毕业证(鲍顿别濒毕业证书)原版定制
taqyea
?
TCP/IP presentation SET2- Information Systems
TCP/IP presentation SET2- Information Systems
agnesegtcagliero
?
PROCESS FOR CREATION OF BUSINESS PARTNER IN SAP
PROCESS FOR CREATION OF BUSINESS PARTNER IN SAP
AhmadAli716831
?
DDoS in India, presented at INNOG 8 by Dave Phelan
DDoS in India, presented at INNOG 8 by Dave Phelan
APNIC
?
BroadLink Cloud Service introduction.pdf
BroadLink Cloud Service introduction.pdf
DevendraDwivdi1
?
BASICS OF SAP _ ALL ABOUT SAP _WHY SAP OVER ANY OTHER ERP SYSTEM
BASICS OF SAP _ ALL ABOUT SAP _WHY SAP OVER ANY OTHER ERP SYSTEM
AhmadAli716831
?
IAREUOUSTPIDWHY$)CHARACTERARERWUEEJJSKWNSND
IAREUOUSTPIDWHY$)CHARACTERARERWUEEJJSKWNSND
notgachabite123
?
Topic 1 Foundational IT Infrastructure_.pptx
Topic 1 Foundational IT Infrastructure_.pptx
oneillp100
?
ChatGPT_and_Its_Uses_Presentationss.pptx
ChatGPT_and_Its_Uses_Presentationss.pptx
Neha Prakash
?
最新版加拿大奎斯特大学毕业证(蚕鲍颁毕业证书)原版定制
最新版加拿大奎斯特大学毕业证(蚕鲍颁毕业证书)原版定制
taqyed
?
The ARUBA Kind of new Proposal Umum .pptx
The ARUBA Kind of new Proposal Umum .pptx
andiwarneri
?
B M Mostofa Kamal Al-Azad [Document & Localization Expert]
B M Mostofa Kamal Al-Azad [Document & Localization Expert]
Mostofa Kamal Al-Azad
?
Clive Dickens RedTech Public Copy - Collaborate or Die
Clive Dickens RedTech Public Copy - Collaborate or Die
Clive Dickens
?
Almos Entirely Correct Mixing with Apps to Voting
Almos Entirely Correct Mixing with Apps to Voting
gapati2964
?
Transmission Control Protocol (TCP) and Starlink
Transmission Control Protocol (TCP) and Starlink
APNIC
?
Make DDoS expensive for the threat actors
Make DDoS expensive for the threat actors
APNIC
?
原版澳洲斯文本科技大学毕业证(厂鲍罢毕业证书)如何办理
原版澳洲斯文本科技大学毕业证(厂鲍罢毕业证书)如何办理
taqyed
?
Pitch PitchPitchPitchPitchPitchPitch.pptx
Pitch PitchPitchPitchPitchPitchPitch.pptx
157551
?
Lecture 3.1 Analysing the Global Business Environment .pptx
Lecture 3.1 Analysing the Global Business Environment .pptx
shofalbsb
?
狠狠撸s: Eco Economic Epochs for The World Game (s) pdf
狠狠撸s: Eco Economic Epochs for The World Game (s) pdf
Steven McGee
?
最新版美国特拉华大学毕业证(鲍顿别濒毕业证书)原版定制
最新版美国特拉华大学毕业证(鲍顿别濒毕业证书)原版定制
taqyea
?
TCP/IP presentation SET2- Information Systems
TCP/IP presentation SET2- Information Systems
agnesegtcagliero
?
PROCESS FOR CREATION OF BUSINESS PARTNER IN SAP
PROCESS FOR CREATION OF BUSINESS PARTNER IN SAP
AhmadAli716831
?
DDoS in India, presented at INNOG 8 by Dave Phelan
DDoS in India, presented at INNOG 8 by Dave Phelan
APNIC
?
BroadLink Cloud Service introduction.pdf
BroadLink Cloud Service introduction.pdf
DevendraDwivdi1
?
BASICS OF SAP _ ALL ABOUT SAP _WHY SAP OVER ANY OTHER ERP SYSTEM
BASICS OF SAP _ ALL ABOUT SAP _WHY SAP OVER ANY OTHER ERP SYSTEM
AhmadAli716831
?
IAREUOUSTPIDWHY$)CHARACTERARERWUEEJJSKWNSND
IAREUOUSTPIDWHY$)CHARACTERARERWUEEJJSKWNSND
notgachabite123
?
Topic 1 Foundational IT Infrastructure_.pptx
Topic 1 Foundational IT Infrastructure_.pptx
oneillp100
?
ChatGPT_and_Its_Uses_Presentationss.pptx
ChatGPT_and_Its_Uses_Presentationss.pptx
Neha Prakash
?
最新版加拿大奎斯特大学毕业证(蚕鲍颁毕业证书)原版定制
最新版加拿大奎斯特大学毕业证(蚕鲍颁毕业证书)原版定制
taqyed
?
The ARUBA Kind of new Proposal Umum .pptx
The ARUBA Kind of new Proposal Umum .pptx
andiwarneri
?
B M Mostofa Kamal Al-Azad [Document & Localization Expert]
B M Mostofa Kamal Al-Azad [Document & Localization Expert]
Mostofa Kamal Al-Azad
?
Clive Dickens RedTech Public Copy - Collaborate or Die
Clive Dickens RedTech Public Copy - Collaborate or Die
Clive Dickens
?
Almos Entirely Correct Mixing with Apps to Voting
Almos Entirely Correct Mixing with Apps to Voting
gapati2964
?
Transmission Control Protocol (TCP) and Starlink
Transmission Control Protocol (TCP) and Starlink
APNIC
?
Make DDoS expensive for the threat actors
Make DDoS expensive for the threat actors
APNIC
?
原版澳洲斯文本科技大学毕业证(厂鲍罢毕业证书)如何办理
原版澳洲斯文本科技大学毕业证(厂鲍罢毕业证书)如何办理
taqyed
?
Pitch PitchPitchPitchPitchPitchPitch.pptx
Pitch PitchPitchPitchPitchPitchPitch.pptx
157551
?
Ad

Internet Routing Security