Currently free during beta - premium features coming soon. Subscribe now to lock in early access.

arXiv: The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Software

AI_SAFETY AI Security & Safety · · arxiv_cscr

AI Analysis

A new academic paper published on arXiv, titled "The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Software," has identified critical security flaws in the Resource Public Key Infrastructure (RPKI) protocol and its implementations. RPKI is a key internet infrastructure used to secure Border Gateway Protocol (BGP) routing by cryptographically verifying IP address ownership. The paper reveals that both the specification and widely used open-source RPKI software contain design weaknesses that could allow attackers to manipulate routing decisions, potentially leading to traffic interception, denial of service, or route hijacking.

This vulnerability primarily affects internet service providers, cloud service providers, content delivery networks, financial institutions, and any organization that relies on BGP routing for critical network operations. National regulatory bodies and telecommunications authorities in the EU should also take note, as RPKI is increasingly mandated or recommended under network security frameworks like the EU's NIS2 Directive and the proposed Cyber Resilience Act. Organizations that have deployed RPKI validation or rely on RPKI-based route origin validation are directly exposed.

Compliance teams should immediately assess whether their network infrastructure uses RPKI software or services from affected vendors. They should review the paper for specific software versions and configuration weaknesses, and coordinate with network security teams to apply patches or workarounds as they become available. Additionally, teams should update their incident response plans to account for potential BGP hijacking scenarios and ensure that RPKI-related controls are included in upcoming regulatory audits under NIS2 or sector-specific cybersecurity requirements.

Get notified about AI_SAFETY changes

Subscribe to our free weekly digest covering 24 compliance frameworks.