collaborators
Showing cs.CRShow all

7 papers · 1 filter

cs.CR2026

The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Software

Oliver Jacobsen, Tobias Kirsch, Haya Schulmann +2

The Resource Public Key Infrastructure (RPKI) secures the Internet's routing system by defining a complex trust and validation framework for certificates, Route Origin Authorizatio…

cs.CR2024

Poster: From Fort to Foe: The Threat of RCE in RPKI

Oliver Jacobsen, Haya Schulmann, Niklas Vogel +1

In this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine runn…

cs.CR2024

RPKI: Not Perfect But Good Enough

Haya Schulmann, Niklas Vogel, Michael Waidner

The Resource Public Key Infrastructure (RPKI) protocol was standardized to add cryptographic security to Internet routing. With over 50% of Internet resources protected with RPKI t…

cs.CR2024

SoK: An Introspective Analysis of RPKI Security

Donika Mirdita, Haya Schulmann, Michael Waidner

The Resource Public Key Infrastructure (RPKI) is the main mechanism to protect inter-domain routing with BGP from prefix hijacks. It has already been widely deployed by large provi…

cs.CR2024

Attacking with Something That Does Not Exist: 'Proof of Non-Existence' Can Exhaust DNS Resolver CPU

Olivia Gruza, Elias Heftrig, Oliver Jacobsen +3

NSEC3 is a proof of non-existence in DNSSEC, which provides an authenticated assertion that a queried resource does not exist in the target domain. NSEC3 consists of alphabetically…

cs.CR2024

The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSEC

Elias Heftrig, Haya Schulmann, Niklas Vogel +1

Availability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you…