Who's got my back? Measuring the adoption of an internet-wide BGP RTBH Service

Journal Article (2024)
Author(s)

R.I. Anghel (TU Delft - Organisation & Governance)

Y. Zhauniarovich (TU Delft - Organisation & Governance)

Carlos Ganan (TU Delft - Organisation & Governance)

Research Group
Organisation & Governance
Copyright
© 2024 R.I. Anghel, Y. Zhauniarovich, C. Hernandez Ganan
DOI related publication
https://doi.org/10.1145/3639029
More Info
expand_more
Publication Year
2024
Language
English
Copyright
© 2024 R.I. Anghel, Y. Zhauniarovich, C. Hernandez Ganan
Research Group
Organisation & Governance
Issue number
1
Volume number
8
Pages (from-to)
1-25
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Distributed Denial-of-Service (DDoS) attacks continue to threaten the availability of Internet-based services. While countermeasures exist to decrease the impact of these attacks, not all operators have the resources or knowledge to deploy them. Alternatively, anti-DDoS services such as DDoS clearing houses and blackholing have emerged. Unwanted Traffic Removal Service (UTRS), being one of the oldest community-based anti-DDoS services, has become a global free collaborative service that aims at mitigating major DDoS attacks through the Border Gateway Protocol (BGP). Once the BGP session with UTRS is established, UTRS members can advertise part of the prefixes belonging to their AS to UTRS. UTRS will forward them to all other participants, who, in turn, should start blocking traffic to the advertised IP addresses. In this paper, we develop and evaluate a methodology to automatically detect UTRS participation in the wild. To this end, we deploy a measurement infrastructure and devise a methodology to detect UTRS-based traffic blocking. Using this methodology, we conducted a longitudinal analysis of UTRS participants over ten weeks. Our results show that at any point in time, there were 562 participants, including multihomed, stub, transit, and IXP ASes. Moreover, we surveyed 245 network operators to understand why they would (not) join UTRS. Results show that threat and coping appraisal significantly influence the intention to participate in UTRS.