Linchakin

FCC looks into BGP vulnerabilities in light of Russian hacking threat

 March 02, 2022     No comments   

The FCC is launching an inquiry into security issues surrounding the Border Gateway Protocol (BGP), a widely used standard used to manage interconnectivity between large portions of the Internet.

The move, announced Monday, was issued in response to "Russia's escalating actions inside of Ukraine," according to the commission's notice of inquiry.

BGP is, in essence, a method of ensuring that independently managed networks that make up the global internet are able to communicate with one another. Its initial design, which the FCC said is still in widespread use today, does not contain important security features, meaning that, simply by misconfiguring its own BGP information, a bad actor could potentially redirect Internet traffic wherever it sees fit. This could let that attacker send incorrect information to its targets, read and compromise login credentials, or simply shut down whichever kinds of traffic it wishes.

The potential consequences of a BGP hack are extreme, the FCC said, noting that the types of network effects such an attack can cause include fallout for critical infrastructure like financial markets, transportation and utility systems.

There are security frameworks out there for BGP — the Internet Engineering Task Force and National Institute of Standards and Technology have both created several standards to make BGP more secure, among other projects with that aim in mind — but the FCC said that many networks have not taken advantage of them and remain vulnerable.

Hence, the commission's inquiry has several goals, including the identification of the possible harms that could result from malicious attacks on BGP, methods of monitoring for BGP attacks, and any potential ways to accelerate the deployment of security standards for BGP.

"Ensuring continued U.S. leadership requires that we explore opportunities to spur trustworthy innovation for more secure communications and critical infrastructure," the FCC said.

BGP hijacks can occur by mistake, rather than through malicious activity — but either way, their effect can be far-reaching. One incident, in April 2020, saw traffic meant for some of the biggest names on the internet, including Google, Facebook and Amazon, briefly redirected through Russia's state-owned ISP, Rostelecom.

A second "hijack" that same month sent traffic to Rostelecom from Visa and Mastercard, among others. The Mutually Agreed Norms for Routing Security (or MANRS) project, run by the Internet Society, said that it identified about 775 incidents as possible BGP hijacks in 2021 alone.

"The FCCs announcement is about issues inherent to BGP but it also applies to the ecosystem of network providers and operators. It asks for comments on security mitigations, controls, and the degree of regulatory oversight necessary across the ecosystem of network operators and providers (and quite a bit more than that)," said Forrester Vice President and Principal Analyst Jeff Pollard.

 "This is less about discovering what's new or interesting with respect to BGP and more about building momentum to make necessary changes that make BGP more secure given its importance. The internet doesn't work without it," Pollard said.

This story, "FCC looks into BGP vulnerabilities, in light of Russian hacking threat" was originally published by CSO Online .

Join the Network World communities on Facebook and LinkedIn to comment on topics that are top of mind.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • Copic marker Black Friday: all the best cheap marker dealsByJess Weatherbed 04 November 2021Black FridayWhere to find cheap Copic marker pens and sets... You might not know that Copic marker Black Friday was a thing, but let us assure that it is, and it's worth holding on for. Finding deals on cheap Co… Read More
  • 55-inch TV now just $228 in killer early Black Friday dealByBeren Neale 04 November 2021dealsIt's 4K too! Retailers are throwing out the rule book this November, and starting Black Friday deals earlier than ever, as this Walmart TV deal proves: buy the TC… Read More
  • MSI Unveils Curved Display with Quantum Dots, Mini LEDs and DisplayHDR 1000ByAnton Shilov 04 November 2021MSI launches 34-inch curved Mini LED LCD, pr...MSI on Thursday revealed the industry's first curved display that features mini LED backlighting with quantum dot films and complies with VESA's Displ… Read More
  • "Sexualised" ketchup bottle causes uproar - but is it really that bad?ByAmelia Bamsey 04 November 2021NewsShake, Squeeze and...what?The last thing we thought we would be writing about today was an over-sexualised ketchup bottle. (No, seriously, this is stupid. We can't believe we'r… Read More
  • New Windows 11 Bug Prevents Snipping Tool and Built-In Apps From OpeningByAaron Klotz 04 November 2021Microsoft has confirmed a major problem with Win... A new bug has appeared for Windows 11 that prevents Microsoft's built-in applications like the Snipping tool, touch keyboard, and method editor from … Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates