What Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation requires
This special publication on Resilient Interdomain Traffic Exchange (RITE) includes initial guidance on securing the interdomain routing control traffic, preventing IP address spoofing, and certain aspects of DoS/DDoS detection and mitigation. The primary focus of these recommendations are the points of interconnection between enterprise networks, or hosted service providers, and the public internet. The primary audience includes information security officers and managers of federal enterprise networks. The guidance also applies to the network services of hosting providers and internet service providers (ISPs) when they are used to support federal IT systems. The core recommendations reduce the risk of accidental and malicious attacks in the routing control plane, and they help detect and prevent IP address spoofing and resulting DoS/DDoS attacks. Technologies recommended for securing interdomain routing control traffic include Resource Public Key Infrastructure (RPKI), BGP origin validation (BGP-OV), and prefix filtering. Additionally, technologies recommended for mitigating DoS/DDoS attacks include prevention of IP address spoofing using source address validation (SAV) with access control lists (ACLs) and unicast Reverse Path Forwarding (uRPF). Other technologies such as remotely triggered black hole (RTBH) filtering, flow specification (Flowspec), and response rate limiting (RRL) are also recommended as part of the overall security mechanisms.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-189.pdf
SHA-256 integrity: 68c77df32cfd1bb8677ddc8b03a9b20e15b4d5fda80c82fe71907593f793b8fa
Primary Citations — 7 traced to source
- Security Recommendation 1: All internet number resources (e.g., address blocks and AS numbers) should be covered by an appropriate registration services agreement with an RIR, and all point-of-contact (POC) information should be up to date.
- Security Recommendation 4: Internet number resource holders with IPv4/IPv6 prefixes and/or AS numbers (ASNs) should obtain RPKI certificate(s) for their resources.
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access