{"id":5151,"date":"2024-09-04T16:34:14","date_gmt":"2024-09-04T21:34:14","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/white-house-unveils-roadmap-to-fix-bgp"},"modified":"2024-09-04T16:34:14","modified_gmt":"2024-09-04T21:34:14","slug":"white-house-unveils-road-map-to-fix-bgp","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/04\/white-house-unveils-road-map-to-fix-bgp\/","title":{"rendered":"White House Unveils Road Map to Fix BGP"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt92637d3cb418f6b8\/664de8c790268e10c164ad37\/Global-network%281800%29_Porntep_Lueangon_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The White House outlined a plan for addressing internet routing security issues, including vulnerabilities associated with the Border Gateway Protocol (BGP). The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/oncd\/briefing-room\/2024\/09\/03\/press-release-white-house-office-of-the-national-cyber-director-releases-roadmap-to-enhance-internet-routing-security\/\" rel=\"noopener\">Roadmap to Enhancing Internet Routing Security<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from the White House Office of the National Cyber Director (ONCD) is part of the broader <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2024\/05\/National-Cybersecurity-Strategy-Implementation-Plan-Version-2.pdf\" rel=\"noopener\">National Cybersecurity Strategy Implementation Plan<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to secure the foundation of the Internet.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BGP \u2014 the protocol used for exchanging routing information on the Internet \u2014 can be hijacked to divert traffic to disrupt critical infrastructure, intercept information, or conduct espionage. Because BGP does not have a way to verify the authenticity of route announcements or network paths, it is possible to publish a new network path and thus move traffic through hostile networks. Several potential vulnerabilities in BGP have also been disclosed over the past few years.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BGP mistakes are common \u2014 as when Microsoft accidentally published incorrect route information that made Microsoft Azure and other Microsoft cloud service unavailable for about 90 minutes back in 2023, or when a small internet service provider accidentally became the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.cloudflare.com\/how-verizon-and-a-bgp-optimizer-knocked-large-parts-of-the-internet-offline-today\/\" rel=\"noopener\">preferred route to reach Cloudflare<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> back in 2019. Re-routing can be potentially hostile, as when China Telecom in 2010 routed 15% of the world\u2019s traffic through its servers for 18 minutes, or when threat actors hijacked DNS traffic from Amazon Web Services to steal approximately $150,000 in cryptocurrency from MyEtherWallet users in 2018.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Using RPKI to Fix BGP\">Using RPKI to Fix BGP<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ONCD encouraged adopting Resource Public Key Infrastructure (RPKI) to improve BGP security. The proposed roadmap describes baseline actions for all network operators, network service providers, and government entities. Actions include developing and maintaining a cybersecurity risk management plan and setting up RPKI components on their networks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The White House is not the only one looking at BGP. The FCC also recently proposed a plan for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.fcc.gov\/document\/fcc-proposes-internet-routing-security-reporting-requirements\" rel=\"noopener\">broadband providers to create and implement plans<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to mitigate BGP issues.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">RPKI\u2019s two main components, Route Origin Authorizations and Route Origin Validation, help ensure that traffic does not get rerouted when it should not be. Route Origin Authorization is a signed certificate authorizing a network to announce a specific IP block. Networks also use Route Origin Validation to check Route Origin Authorizations and filter out invalid BGP announcements. For Route Origin Authorization to be effective, there has to be widespread deployment of Route Origin Validation throughout the Internet.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Speed Up RPKI Adoption\">Speed Up RPKI Adoption<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The good news is that the majority of BGP route originations globally are already Route Origin Validation-valid, and the percentage of traffic covered by Route Origin Authorization is over 70%, according to statistics cited by the ONCD.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, there remains more to be done, as some large networks in the United States have not yet implemented RPKI. According to data from NIST&#8217;s RPKI Monitor, only 39% of IP prefixes originated by US networks have a valid Route Origin Authorization. They include networks of several commercial providers and the US government. The goal is to have 60% of the federal government\u2019s advertised IP space be covered by the Registration Service Agreements necessary to establish Route Origin Authorizations by the end of the year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If the low rate of ROA creation and adoption among these few but large network operators that hold a dominant share of North American address space were rectified, BGP security and resilience in the region would substantially improve,&#8221; the ONCD said.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Policy changes such as requiring the government contractors and service providers to use RPKI could help push the needle forward. &#8220;[Office of Management and Budget] should require the Federal Government\u2019s contracted service providers to adopt and deploy current commercially-viable Internet routing security technologies,&#8221; the ONCD wrote in the roadmap. Additionally, grant programs &#8220;should require grant recipients to incorporate routing security measures into their projects.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a blog post, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.cloudflare.com\/white-house-routing-security\/\" rel=\"noopener\">Cloudflare urged network operators<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to sign Route Origin Authorization records and performing Route Origin Validation on their networks. Non-network operators can check whether their Internet service provider has secured BGP via <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"http:\/\/isbgpsafeyet.com\/\" rel=\"noopener\">isbgpsafeyet.com<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;From an implementation standpoint, our hope is that the government\u2019s focus on routing security through all the levers outlined in the roadmap will speed up ROA adoption, and encourage wider implementation of ROV and other best practices,&#8221; Cloudflare&#8217;s Mike Conlow, Emily Music, and Tom Strickx wrote.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/white-house-unveils-roadmap-to-fix-bgp\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The White House outlined a plan for addressing internet routing<\/p>\n","protected":false},"author":12,"featured_media":5152,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5151","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=1820%2C1023&ssl=1",1820,1023,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=1536%2C863&ssl=1",1536,863,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=1820%2C1023&ssl=1",1820,1023,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/09\/white-house-unveils-road-map-to-fix-bgp.jpg?fit=1820%2C1023&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5151"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5151\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5152"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}