Internet Exchange Points (IXPs) are crucial components of the Internet ecosystem, enabling efficient interconnection among Autonomous Systems (ASes). Their operation relies on Route Servers (RSes), which simplify public peering by allowing ASes to maintain a single Border Gateway Protocol (BGP) session rather than multiple bilateral ones. However, BGP's reliance on implicit trust exposes it to vulnerabilities that can be exploited to hijack or disrupt traffic. To mitigate these risks, IXPs deploy filtering mechanisms based on Internet Routing Registries (IRRs) and the Resource Public Key Infrastructure (RPKI). Current practices exhibit a critical blind spot: IRR-based filtering heavily relies on AS-SET objects, failing to bind IP prefixes to their legitimate AS, allowing hijacks to evade detection. In this work, we formally define and analyze this vulnerability, showing how it can be exploited to perform prefix hijacking via IXPs. We quantify its prevalence across the EURO-IX community and validate our findings using real-world data from the RSes of two major European IXPs, AMS-IX and NAMEX. Finally, we propose practical countermeasures to strengthen RS filtering.

Exploring the blind spot of internet exchange point route servers / Servillo, S., Spadaccino, P., Konstantaras, S., Luciani, F., Cuomo, F.. - (2026). (IEEE/IFIP Network Operations and Management Symposium 2026 Rome; Italy ) [10.1109/NOMS69089.2026.11668306].

Exploring the blind spot of internet exchange point route servers

Stefano Servillo
;
Pietro Spadaccino;Francesca Cuomo
2026

Abstract

Internet Exchange Points (IXPs) are crucial components of the Internet ecosystem, enabling efficient interconnection among Autonomous Systems (ASes). Their operation relies on Route Servers (RSes), which simplify public peering by allowing ASes to maintain a single Border Gateway Protocol (BGP) session rather than multiple bilateral ones. However, BGP's reliance on implicit trust exposes it to vulnerabilities that can be exploited to hijack or disrupt traffic. To mitigate these risks, IXPs deploy filtering mechanisms based on Internet Routing Registries (IRRs) and the Resource Public Key Infrastructure (RPKI). Current practices exhibit a critical blind spot: IRR-based filtering heavily relies on AS-SET objects, failing to bind IP prefixes to their legitimate AS, allowing hijacks to evade detection. In this work, we formally define and analyze this vulnerability, showing how it can be exploited to perform prefix hijacking via IXPs. We quantify its prevalence across the EURO-IX community and validate our findings using real-world data from the RSes of two major European IXPs, AMS-IX and NAMEX. Finally, we propose practical countermeasures to strengthen RS filtering.
2026
IEEE/IFIP Network Operations and Management Symposium 2026
BGP; routing security; IXPs; AS-SET
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
Exploring the blind spot of internet exchange point route servers / Servillo, S., Spadaccino, P., Konstantaras, S., Luciani, F., Cuomo, F.. - (2026). (IEEE/IFIP Network Operations and Management Symposium 2026 Rome; Italy ) [10.1109/NOMS69089.2026.11668306].
File allegati a questo prodotto
File Dimensione Formato  
Servillo_Exploring_2026.pdf

solo gestori archivio

Tipologia: Documento in Post-print (versione successiva alla peer review e accettata per la pubblicazione)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 337.98 kB
Formato Adobe PDF
337.98 kB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1767056
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact