RFC 7132: Threat Model for BGP Path Security
In plain English — editorial summary, not part of the RFC
This document describes a threat model for the context in which External Border Gateway Protocol (EBGP) path security mechanisms will be developed. The threat model includes an analysis of the Resource Public Key Infrastructure (RPKI) and focuses on the ability of an Autonomous System (AS) to verify the authenticity of the AS path info received in a BGP update. We use the term "PATHSEC" to refer to any BGP path security technology that makes use of the RPKI. PATHSEC will secure BGP, consistent with the inter-AS security focus of the RPKI. The document characterizes classes of potential adversaries that are considered to be threats and examines classes of attacks that might be launched against PATHSEC. It does not revisit attacks against unprotected BGP, as that topic has already been addressed in the BGP-4 standard. It concludes with a brief discussion of residual vulnerabilities.
Document record
- Document ID
- RFC7132
- Published
- February 2014
- Authors
- S. Kent; A. Chi
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- rtg
- Pages
- 20
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6916Algorithm Agility Procedure for the Resource Public Key Infrastructure (RPKI)Current
April 2013
- RFC 6491Resource Public Key Infrastructure (RPKI) Objects Issued by IANACurrent
February 2012
- RFC 8206BGPsec Considerations for Autonomous System (AS) MigrationCurrent
September 2017
- RFC 8416Simplified Local Internet Number Resource Management with the RPKI (SLURM)Current
August 2018
- RFC 6382Unique Origin Autonomous System Numbers (ASNs) per Node for Globally Anycasted ServicesCurrent
October 2011
- RFC 6811BGP Prefix Origin ValidationUpdated
January 2013
- RFC 7730Resource Public Key Infrastructure (RPKI) Trust Anchor LocatorObsoleted
January 2016
- RFC 6493The Resource Public Key Infrastructure (RPKI) Ghostbusters RecordCurrent
February 2012
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?