[Sidrops] Re: Fw: New Version Notification for draft-li-sidrops-stealthy-hijacking-01.txt

Yihao Chen <yh-chen21@mails.tsinghua.edu.cn> Sat, 11 October 2025 04:04 UTC

Return-Path: <yh-chen21@mails.tsinghua.edu.cn>
X-Original-To: sidrops@mail2.ietf.org
Delivered-To: sidrops@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A84137141530 for <sidrops@mail2.ietf.org>; Fri, 10 Oct 2025 21:04:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=mails.tsinghua.edu.cn
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l3Ne-sYBd854 for <sidrops@mail2.ietf.org>; Fri, 10 Oct 2025 21:04:37 -0700 (PDT)
Received: from tsinghua.edu.cn (smtp47.tsinghua.edu.cn [101.6.4.71]) by mail2.ietf.org (Postfix) with ESMTP id 980817141527 for <sidrops@ietf.org>; Fri, 10 Oct 2025 21:04:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mails.tsinghua.edu.cn; s=dkim; h=Received:Date:From:To:Cc: Subject:In-Reply-To:References:Content-Type:MIME-Version: Message-ID; bh=+2s5thd8mEaWROhSAd5Jwg0np7v1f7/ckzYOz/qxDXQ=; b=I WIoH/cSalzMxgvx2DRIuMtx4wy314P4X3+tNSOLiLC0q6LNBP5i4lgxTvMqiFHvl L0ssLNstdVTceAfmZ3NYsfRSoSTZX1q/OsIR9Al6NunBmXMIs8ZBefqxOTRVrk9b p8zDrMRCaXOOEd3P/JfimsQoLm5ywJDnHqKSESfli4=
Received: from yh-chen21$mails.tsinghua.edu.cn ( [183.173.146.68] ) by ajax-webmail-web4 (Coremail) ; Sat, 11 Oct 2025 12:04:32 +0800 (GMT+08:00)
X-Originating-IP: [183.173.146.68]
Date: Sat, 11 Oct 2025 12:04:32 +0800
X-CM-HeaderCharset: UTF-8
From: Yihao Chen <yh-chen21@mails.tsinghua.edu.cn>
To: "Li, Weitong" <weitongli@vt.edu>
X-Priority: 3
X-Mailer: Coremail Webmail Server Version 2024.2-cmXT5 build 20250909(015d6f0a) Copyright (c) 2002-2025 www.mailtech.cn mispb-4df55a87-4b50-4a66-85a0-70f79cb6c8b5-tsinghua.edu.cn
In-Reply-To: <SJ0PR05MB748632DF1FEE15F06D7F77CDCEEFA@SJ0PR05MB7486.namprd05.prod.outlook.com>
References: <176007306066.701.17529468141555810880@dt-datatracker-84f8f646b-tg6mn> <29002c80.1c811.199cc9e2cfc.Coremail.yh-chen21@mails.tsinghua.edu.cn> <SJ0PR05MB748632DF1FEE15F06D7F77CDCEEFA@SJ0PR05MB7486.namprd05.prod.outlook.com>
Content-Type: multipart/alternative; boundary="----=_Part_429350_200138266.1760155472114"
MIME-Version: 1.0
Message-ID: <2a14756c.1e06b.199d17110f2.Coremail.yh-chen21@mails.tsinghua.edu.cn>
X-Coremail-Locale: en_US
X-CM-TRANSID: ywQGZQCXdqRQ1+loXacGAw--.18911W
X-CM-SenderInfo: l1knuxlhqsiqxpdlz2oowvx0pjkxthxhgxhubq/1tbiAgIMBGjpqs RlXQABse
X-Coremail-Antispam: 1Ur529EdanIXcx71UUUUU7IcSsGvfJ3iIAIbVAYjsxI4VWxJw CS07vEb4IE77IF4wCS07vE1I0E4x80FVAKz4kxMIAIbVAFxVCaYxvI4VCIwcAKzIAtYxBI daVFxhVjvjDU=
Message-ID-Hash: R6DEYKOVN3BGVSYLK3YHOUTGDUTWOQ2K
X-Message-ID-Hash: R6DEYKOVN3BGVSYLK3YHOUTGDUTWOQ2K
X-MailFrom: yh-chen21@mails.tsinghua.edu.cn
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-sidrops.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: "sidrops@ietf.org" <sidrops@ietf.org>, "qli01@tsinghua.edu.cn" <qli01@tsinghua.edu.cn>, "zhuotaoliu@tsinghua.edu.cn" <zhuotaoliu@tsinghua.edu.cn>, "xuke@tsinghua.edu.cn" <xuke@tsinghua.edu.cn>, "jianping@cernet.edu.cn" <jianping@cernet.edu.cn>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Sidrops] Re: Fw: New Version Notification for draft-li-sidrops-stealthy-hijacking-01.txt
List-Id: A list for the SIDR Operations WG <sidrops.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/sidrops/lcSmZ6OGb6Ezz3OAo1s7RBax8ew>
List-Archive: <https://mailarchive.ietf.org/arch/browse/sidrops>
List-Help: <mailto:sidrops-request@ietf.org?subject=help>
List-Owner: <mailto:sidrops-owner@ietf.org>
List-Post: <mailto:sidrops@ietf.org>
List-Subscribe: <mailto:sidrops-join@ietf.org>
List-Unsubscribe: <mailto:sidrops-leave@ietf.org>

Hi Weitong,




Thanks. I'll look into these papers and update the draft accordingly.




Regarding the term, I feel that "collateral damage" gives the impression that RPKI/ROV itself causes the damage. If it's meant that way, it feels more natural to me to interpret the damage as disconnection rather than traffic diversion caused by hijacking, since traffic diversion is the result of ROV protection failure rather than additional damage. In fact, the additional damage (drawback) is the increased stealthiness of BGP hijacking. What do you think?




Best,

Yihao

-----Original Messages-----
From:"Li, Weitong" <weitongli@vt.edu>
Send time:Saturday, 11/10/2025 02:12:33
To: "Yihao Chen" <yh-chen21@mails.tsinghua.edu.cn>, "sidrops@ietf.org" <sidrops@ietf.org>
Cc: "qli01@tsinghua.edu.cn" <qli01@tsinghua.edu.cn>, "zhuotaoliu@tsinghua.edu.cn" <zhuotaoliu@tsinghua.edu.cn>, "xuke@tsinghua.edu.cn" <xuke@tsinghua.edu.cn>, "jianping@cernet.edu.cn" <jianping@cernet.edu.cn>
Subject: [Sidrops] Re: Fw: New Version Notification for draft-li-sidrops-stealthy-hijacking-01.txt


Hi Yihao,


There're some measurement works for "stealth BGP hijacking" that might be helpful.
(they are focusing on "collateral damage of partial ROV deployment" but I believe it's same with what you call "stealth BGP hijacking").


simulation based measurement:  NDSS'16 Are We There Yet? On RPKI’s Deployment and Security
real-world measurement: Sec'25 ImpROV: Measurement and Practical Mitigation of Collateral Damage in RPKI Route Origin Validation


Best,
Weitong




From: Yihao Chen <yh-chen21@mails.tsinghua.edu.cn>
Sent: Friday, October 10, 2025 1:35 AM
To: sidrops@ietf.org <sidrops@ietf.org>
Cc: qli01@tsinghua.edu.cn <qli01@tsinghua.edu.cn>; zhuotaoliu@tsinghua.edu.cn <zhuotaoliu@tsinghua.edu.cn>; xuke@tsinghua.edu.cn <xuke@tsinghua.edu.cn>; jianping@cernet.edu.cn <jianping@cernet.edu.cn>
Subject: [Sidrops] Fw: New Version Notification for draft-li-sidrops-stealthy-hijacking-01.txt
 
Hi all,

We have submitted a new version of draft-li-sidrops-stealthy-hijacking, with revised/added texts on mitigations against stealthy BGP hijacking. We believe it is relevant to SIDROPS WG and would like to hear your feedback.

Revision summary:
1. Rewrote the description of ROV++ for better clarity and detail. The revised version now elaborates on how an enforcing AS, upon detecting an RPKI-invalid route, initiates a proactive rerouting process to find alternative paths avoiding risk-critical ASes.
2. Incorporated descriptions of Jakob's patent, which introduces a poison-path routing policy that can mitigate stealth BGP hijacking. This policy allows any AS (not only ROV adopters) to reroute traffic away from paths that might divert traffic to hijacked prefixes.
3. Highlighted the importance of transparency regarding dropped routes, noting that nondeterministic overwriting of routing policies can be too aggressive. The revision proposes information-sharing mechanisms as a means to increase visibility into routing anomalies and assist victims in identifying risks and determining their own response actions.

Your comments are welcome. Thank you.

Best,
Yihao Chen

> -----Original Messages-----
> From: internet-drafts@ietf.org
> Send time:Friday, 10/10/2025 13:11:00
> To: "Jianping Wu" <jianping@cernet.edu.cn>, "Ke Xu" <xuke@tsinghua.edu.cn>, "Li Qi" <qli01@tsinghua.edu.cn>, "Qi Li" <qli01@tsinghua.edu.cn>, "Yihao Chen" <yh-chen21@mails.tsinghua.edu.cn>, "Zhuotao Liu" <zhuotaoliu@tsinghua.edu.cn>, "Zhuotao liu" <zhuotaoliu@tsinghua.edu.cn>
> Subject: New Version Notification for draft-li-sidrops-stealthy-hijacking-01.txt
>
> A new version of Internet-Draft draft-li-sidrops-stealthy-hijacking-01.txt has
> been successfully submitted by Yihao Chen and posted to the
> IETF repository.
>
> Name:     draft-li-sidrops-stealthy-hijacking
> Revision: 01
> Title:    Risk of Stealthy BGP Hijacking under Incomplete Adoption of Route Origin Validation (ROV)
> Date:     2025-10-10
> Group:    Individual Submission
> Pages:    13
> URL:      https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-li-sidrops-stealthy-hijacking-01.txt&data=05%7C02%7Cweitongli%40vt.edu%7C9d0ae3f0e8234821643508de07bee871%7C6095688410ad40fa863d4f32c1e3a37a%7C0%7C0%7C638956713812033294%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=uIMEDoQ6nyRYyYa7pt2qE7zWm%2FRwtJzdJyRCk9jCgUg%3D&reserved=0
> Status:   https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-li-sidrops-stealthy-hijacking%2F&data=05%7C02%7Cweitongli%40vt.edu%7C9d0ae3f0e8234821643508de07bee871%7C6095688410ad40fa863d4f32c1e3a37a%7C0%7C0%7C638956713812060417%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=sM0kF4rNM3UvKG5OBb2gNl7T1tKMWjsifUfzrNk7IPU%3D&reserved=0
> HTMLized: https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-li-sidrops-stealthy-hijacking&data=05%7C02%7Cweitongli%40vt.edu%7C9d0ae3f0e8234821643508de07bee871%7C6095688410ad40fa863d4f32c1e3a37a%7C0%7C0%7C638956713812077976%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=5fAmI57RuvJ29On2gnc1Y8Z%2Ba0fZqU6xldSdVwyl0Cg%3D&reserved=0
> Diff:     https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fauthor-tools.ietf.org%2Fiddiff%3Furl2%3Ddraft-li-sidrops-stealthy-hijacking-01&data=05%7C02%7Cweitongli%40vt.edu%7C9d0ae3f0e8234821643508de07bee871%7C6095688410ad40fa863d4f32c1e3a37a%7C0%7C0%7C638956713812093336%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=PqS7DfOVbWJsd9Uv7uMft57XstbGJiBAdBbuoA1cqyw%3D&reserved=0
>
> Abstract:
>
>    This document describes how incomplete adoption of Route Origin
>    Validation (ROV) makes certain forms of BGP hijacking less visible on
>    the control plane while still capable of diverting traffic.  We
>    explain the underlying mechanism, define the form of the threat,
>    analyze an real-world incident that exemplifies the issue, and
>    discuss potential countermeasures to mitigate its impact.
>
>
>
> The IETF Secretariat
>
_______________________________________________
Sidrops mailing list -- sidrops@ietf.org
To unsubscribe send an email to sidrops-leave@ietf.org