internet resource certification (rpki)slides.lacnic.net/wp-content/themes/slides/docs/...rpki...

31
Sint-Maarten Internet Week Carlos Mar2nez Cagnazzo carlos @ lacnic.net Internet Resource Certification (RPKI) Building a More Secure Internet

Upload: others

Post on 16-Aug-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

Sint-MaartenInternetWeekCarlosMar2nezCagnazzo

[email protected]

Internet Resource Certification (RPKI) Building a More Secure Internet

Page 2: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

A9acksonrou;ng:IPhijacks

Page 3: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

HowInternetnumberresourcesaremanaged

IANA

ARIN

ISP

Endusers

LACNIC

NIC.br NIC.MX

ISPmx

ISP#1

APNIC

LIRs/ISPs

RIPENCC

LIRs/ISPs

AfriNIC

Page 4: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

HowInternetnumberresourcesaremanaged(ii)

•  Whatdowemeanbyresources–  IPv4Addresses–  IPv6Addresses–  AutonomousSystemNumbers

•  Both16and32bits

•  Founda;onaldocument:RFC2050–  “IPRegistryAlloca1onGuidelines”

•  EachRIRistheauthorita(vesourceontherela;onshipbetweenusers/holdersandresources–  EachRIRoperatesaregistrydatabase

Page 5: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ASN 10 ASN 20ASN1

ASN 2

ASN 3

Rou;ngintheInternet

ASN20announces10.1.0.0/16

The10.1.0.016prefix

propagatesacrossASs(viaBGPsessions)

ASN10receivestheprefix10.1.0.0/16 A9ributes:

10.1.0.0/16AS_PATHASN1ASN3ASN20

Page 6: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

Rou;ngintheInternet(ii)

•  BGPchoosesroutesusingadecisionalgorithmandthevaluesoftheavailablea=ributes

•  AS_PATHisalistoftheautonomoussystemsagivenUPDATEhastraversed–  ThefirstentryistheASorigina;ngtheroute("origin-as")

InthiscaseASN20isthe"origin-as"for

10.1/16

ASN 10 ASN 20ASN1

ASN 2

ASN 3

Page 7: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

Whohasthe"right"touseresources?

•  WhenanISPobtainsresourcesfromitsRIR(IPv6/IPv4/ASN):–  TheISPhastono;fyitsupstreamASNswhichprefixesaregoingtobeannouncedviaBGP

–  Thisisusuallydoneviae-mail,webformsorbyupda;nganIRR(InternetRou1ngRegistry)

•  Upstreamsverify(oratleasttheyshould)therightofusefortheannouncedresources–  RIRWHOISText-basedandnotreallysuitableforautoma;cusage

–  IRRWHOISNon-signedinforma;on,li9leaddi;onaltoolsprovidedforverifica;onofusagerightsexceptfornames,phonenumbersandemailPOCs

•  Thisverifica;onprocessissome;mesnotasthoroughasitshouldbe

Page 8: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

Checkingusagerightsforaresource

•  Networkadministrators–  Localchecksinrou;nginfrastructure

•  Requirepreviousstep(registeringtherouteobjectwithanIRR)–  Routerprotec;on–  Rou;ngprotocolintegrity

•  Peerauthen;ca;on

•  Filteringknown-invalidroutes–  RFC1918prefixfiltering–  Bogonfiltering

•  Intheendtheintegrityoftherou;ngsystemdependsonad-hoctrustrela(onshipsbetweenpeers

Page 9: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RouteHijacking

•  Whenanen;typar;cipa;nginInternetrou;ngannouncesaprefixwithoutauthoriza;onwefacearoutehijack

•  Itcanbeeithermaliciousorduetoopera;onalmistakes

•  Somewell-knowncases:–  PakistanTelecomvs.YouTube(2008)–  ChinaTelecom(2010)–  GoogleinEasternEurope(variousASs,2010)–  Someocurrencesinourregion(January/February2011)

Page 10: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RouteHijacking(ii)

AS15358announces200.40/24

AS8158gets200.40.0.0/16

and200.40.235.0/24 200.40.0.0/16AS_PATHASN1ASN3ASN6057

200.40.235.0/24AS_PATHASN1ASN3ASN6057

AS6057

announces200.40/16

AS8158gets200.40.0.0/16

Page 11: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RouteHijacking(iii)•  RIPENCCVideo–  h9p://www.youtube.com/watch?v=IzLPKuAOe50

Page 12: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ResourcePKI

•  ResourcePublicKeyInfraestructure–  Goal:createasystemthatallowsthecer;fica;onofusagerightsforInternetnumberingresources

–  High-leveloverview•  UseofX.509v3cer;ficates•  ApplyRFC3779extensionstothesecer;ficates.TheseextensionsallowInternetresources(IPv4/IPv6/ASNs)fieldswithincer;ficates

•  Awaytoautoma;callyvalidatetheorigin-asofaBGPUPDATE–  Standardiza;onAc;vi;es

•  IETFSIDRworkinggroup–  Implementa;onAc;vi;es

•  RIRs

Page 13: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ResourcePKI(ii)

•  Automatedoriginvalida(onforrouteannouncements

•  Theen;tywithusagerightsforaresourcesignstheorigin-asfieldofaPKIobject

•  ThefollowingproceduresareappliedtovalidateRPKIcer;ficatesandrou;nginforma;onobjects:–  ThecryptographicvalidityoftheRPKIcer;ficatechain(justlikeanyotherPKI)

–  TheCIDRinclusionproper;esofIPaddresses•  Inthiswayitbecomesmoredifficultforathirdpartytoinjectinvaliddataintotherou;ngsystem

Page 14: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ResourcePKI(iii)

Cache

RPKIManagement

System

Repository

Page 15: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ResourcePKI(iv)•  AllRPKIsignedobjectsarelistedinpublicrepositories

•  Aqerverifica;on,theseobjectscanbeusedtoconfigurefilteringinrouters

•  Valida;onProcess–  Signedobjectshavereferencestothecer;ficateusedtosignthem

–  Eachcer;ficatehasapointertoanupperlevelcer;ficate–  Theresourceslistedinacer;ficateMUSTbevalidsubsetsoftheresourceslistedinitsparent'scer;ficate

–  Inthiswayatrustchaincanbetracedtoa"trustanchor"bothcryptographicallyaswellasinCIDRterms

Page 16: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RPKIStructure

LACNICRTALACNICresources

LACNICProduc;on

<<INHERITED>>

ISP#2ISP#2Resources

ROAEndEn;tycert.

ROAEndEn;tycert.

ISP#1ISP#1Resources

EndUserCA#1

(EU#1Resources)

ROAEndEn;tycert.

ROAEndEn;tycert.

RTAistheself-signedcer;ficateinthehierarchy

Signaturechain

Page 17: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RPKIStructure(ii)•  CAs–  Cer;ficate-signingen;ty(CAbit=1)

•  ISPscanusethiscer;ficatetosigntheirclient'scer;ficates

•  Cer;ficateRepository–  Therepositorycontainscer;ficates,CRLs,ROAsandmanifests

–  Accesiblevia“rsync”•  ManagementInterface– Webinterfaceforthosewhoprefer"hosted"mode

Page 18: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RPKIManagementforUsers•  "Hosted"mode

–  LACNICemitstheresourcecer;ficateforanorganiza;onandguardsbothprivateandpublickeys•  Cer;ficatesareemi9edwhenrequestedbyLACNICmemberorganiza;ons

–  UserscanmanagetheirRPKIobjectsusingauser-friendlywebinterfaceprovidedbyLACNIC

•  "Delegated"mode–  Anorganiza;oncreatesitsownresourcecer;ficate–  Thiscer;ficateissubmi9edtoLACNICforsigning.LACNICreturnsthesignedcer;ficate.•  "Up-down"protocol

Page 19: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ServicesprovidedbytheRPKICA•  Emiungchildresourcecer;ficateswhenchangestotheregistrydatabaseoccurorwhensolicitedbyaresourceholder

•  Childcer;ficaterevoca;onwhensolicitedbyaresourceholder

•  CRLperiodicupdate•  Publishingchildcer;ficates,trustanchorandauxiliaryobjectsinapublicrepository(rsync)

Page 20: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ResourceCer;ficate

Page 21: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ROAs•  ROAs:Rou;ngOriginAuthoriza;on–  ROAscontaindataontheallowedorigin-asforasetofprefixes

–  ROAsaresignedusingthecer;ficatesgeneratedbytheRPKI

–  SignedROAsarecopiedtotherepository

Page 22: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ROAs(ii)

•  AsimplifiedROAcontainsthefollowinginforma;on:

•  TheseROAsstatesthat:–  "Theprefix200.40.0.0/17willbeoriginatedbyASN6057andcouldbede-aggregatedupto/20""Thisstatementisvalidstar1ngonJan2,2011un1lJan1,2012"

•  OtherROAcontent–  ROAscontaincryptographicmaterialthatallowsvalida(onoftheROAscontent

Page 23: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ROAs(iii)•  ContentsofaROA–  Anend-en;tycer;ficatewithresources–  Alistof"routeorigina9esta;ons"

ROAEndEn;tyCer;ficate200/8172.17/16

200.40.0.0/20-24->AS100172.17.0.0/16-19->AS100

Page 24: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

ROAs(iii)-Valida;on•  InordertovalidateaROAthreestepshavetobeperformed–  Cryptovalida;onofthepublickeysandsignaturesincludedintheEEcer;ficatesinsideeachROA

–  CIDRinclusioncheckingofresourceslistedintheEEcer;ficate

–  CIDRinclusioncheckingofresourcesintherouteorigina9esta;ons.TheseresourceshavetobeincludedintheresourceslistedintheEEcer;ficate

Page 25: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RPKIinAc;on

UPDATE

Routersassigna"validitystatus"totherouteincludedinan

UPDATE

Cacheperiodicallyupdatestherouter

withalistofvalidatedprefixes

Page 26: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RPKIinAc;on(ii)

•  Thevalida;onprocessissplitintwoparts–  CryptoandCIDRvalida;onofROAsandcer;ficates

•  Performedbythevalida;ncache

–  Valida;onofroutesinBGPUPDATEs•  PerformedbytheBGPspeakersinthenetwork

•  AspecialprotocolcalledRTRisbeingworkedonbytheIETFforRouter-Cachecommunica;on

Page 27: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

RPKIinAc;on(iii)•  Cache–  RepositorycontentisdownloadedviaRSYNC–  Cer;ficatesandROAsarevalidated

•  Cryptographically(signaturechain)•  CorrectCIDRresourceinclusion

•  Intherouters–  Adatabaseofprefix<->origin-asrela;onshipsisbuilt

Page 28: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

BGPinterac;on•  Routersbuildadatabasewiththeinforma;ontheyreceivefromthecaches

•  Thistablecontains–  Prefix– Minlength– Maxlength–  Origin-AS

•  ByapplyingasetofrulesavaliditystatusisassignedtoeachUPDATEprefix

Page 29: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

BGPinterac;on(ii)

IPprefix/[min_len–max_len] OriginAS

172.16.0.0/[16-20] 10

200.0.0.0/[8-21] 20

•  Ifthe"UPDATEpfx"isnotcoveredbyanyentryintheDB->"notfound"

•  Ifthe"UPDATEpfx"iscoveredbyatleastoneentryintheDB,andtheorigin-ASmatchestheASNsintheDB->"valid"

•  Iftheorigin-ASdoesNOTmatch->"invalid"

UPDATE200.0.0.0/9ORIGIN-AS20

VALID

Page 30: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

twi9er.com/LACNICfacebook.com/LACNICyoutube.com/user/lacnicstaffgplusme.at/LACNIC

CASADEINTERNETDELATINOAMÉRICAYELCARIBE

Page 31: Internet Resource Certification (RPKI)slides.lacnic.net/wp-content/themes/slides/docs/...RPKI cer;ficates and rou;ng informaon objects: – The cryptographic validity of the RPKI

Thankyou!