7 papers
The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Software
Oliver Jacobsen, Tobias Kirsch, Haya Schulmann +2
The Resource Public Key Infrastructure (RPKI) secures the Internet's routing system by defining a complex trust and validation framework for certificates, Route Origin Authorizatio…
Poster: From Fort to Foe: The Threat of RCE in RPKI
Oliver Jacobsen, Haya Schulmann, Niklas Vogel +1
In this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine runn…
RPKI: Not Perfect But Good Enough
Haya Schulmann, Niklas Vogel, Michael Waidner
The Resource Public Key Infrastructure (RPKI) protocol was standardized to add cryptographic security to Internet routing. With over 50% of Internet resources protected with RPKI t…
SoK: An Introspective Analysis of RPKI Security
Donika Mirdita, Haya Schulmann, Michael Waidner
The Resource Public Key Infrastructure (RPKI) is the main mechanism to protect inter-domain routing with BGP from prefix hijacks. It has already been widely deployed by large provi…
Attacking with Something That Does Not Exist: 'Proof of Non-Existence' Can Exhaust DNS Resolver CPU
Olivia Gruza, Elias Heftrig, Oliver Jacobsen +3
NSEC3 is a proof of non-existence in DNSSEC, which provides an authenticated assertion that a queried resource does not exist in the target domain. NSEC3 consists of alphabetically…
The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSEC
Elias Heftrig, Haya Schulmann, Niklas Vogel +1
Availability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you…