America’s Federal Communications Commission (FCC) recently announced a proposed rule aimed at strengthening the security of the Border Gateway Protocol (BGP). BGP acts as the internet’s central routing protocol, directing data packets across vast networks to their intended destinations. However, inherent vulnerabilities within BGP have made it a target for malicious actors seeking to disrupt or manipulate internet traffic.
This announcement highlights growing concerns surrounding BGP security and proposes potential solutions. BGP facilitates the flow of internet traffic between disparate networks, but it lacks robust security features. Malicious actors can exploit these vulnerabilities to redirect traffic, launch denial-of-service attacks, or even steal sensitive data.
In recent years, several high-profile BGP hijacking incidents have underscored the urgency of improving BGP security. For instance, in 2018, attackers hijacked BGP routes for popular platforms like YouTube and Github, causing outages for millions of users. These events serve as stark reminders of the potential consequences of inadequate BGP security.
The FCC’s proposed rule would mandate that internet service providers (ISPs) file regular reports detailing their implementation of Resource Public Key Infrastructure (RPKI). RPKI is a security framework that utilises digital certificates to verify the origin of internet traffic. This verification process makes it significantly more difficult for attackers to spoof their identities.
The FCC’s proposal has elicited mixed reactions from the ISP industry. While some ISPs expressed support for the initiative, others raised concerns regarding the cost and complexity of implementing RPKI.
A spokesperson for a major ISP stated that the company “fully endorses the FCC’s efforts to bolster BGP security.” However, they added that “the FCC should provide clear guidelines for ISPs on RPKI implementation. We also urge the FCC to consider the potential financial burdens, particularly for smaller ISPs.”
The FCC is expected to vote on the proposed rule in the coming months. If adopted, it would represent a significant advancement in BGP security. While RPKI is not a perfect solution, it is a valuable tool that can contribute significantly to a more secure internet environment.
Here’s a breakdown of the key aspects of the FCC’s proposal:
- Mandatory ISP Reporting on RPKI Implementation: ISPs would be required to submit reports detailing their RPKI deployment plans, along with data on how they are utilising RPKI to secure their networks.
- FCC Guidance on RPKI Implementation: The FCC would provide guidance to assist ISPs in effectively implementing RPKI.
- Cost Considerations for Smaller ISPs: The FCC acknowledges the potential financial burdens associated with RPKI implementation, particularly for smaller ISPs, and plans to factor these concerns into the final ruling.
The FCC’s announcement is a welcome development. BGP security is a critical issue, and RPKI offers a proven technology to mitigate BGP vulnerabilities. By mandating ISP implementation of RPKI, the FCC sends a strong message of its commitment to safeguarding the internet.
This proposed regulation has the potential to significantly enhance the security of the internet’s core infrastructure. However, successful implementation will hinge on clear guidance for ISPs, alongside measures to address the cost concerns raised by smaller providers. Continued collaboration between the FCC, ISPs, and the cybersecurity community is crucial to ensuring a secure and resilient BGP ecosystem.



