9
1 Internet Society Collaborative Security & MANRS ENOG 10 14 October 2015, Odessa Maarit Palovirta ([email protected] )

Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

1

Internet Society

Collaborative Security & MANRS ENOG 10 – 14 October 2015, Odessa

Maarit Palovirta ([email protected])

Page 2: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

2

Collaborative Security

2

Fostering

Confidence a

nd

Protecting

Opportunitie

s

Collective Responsibility

Fundamental Properties and Values

Think Globally,

Act Locally

Evolution and

Consensus

Page 3: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

3

Routing Resilience Manifesto

aka MANRS

https://www.routingmanifesto.org/

https://www.manrs.org/

Page 4: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

4

Mutually Agreed Norms for Routing Security (MANRS) • Voluntary, bottom-up agreement between network operators

v Aims to improve the security of the Internet's routing system

• Builds a visible community of security-minded operators v Promotes culture of collaborative responsibility

• Defines four concrete actions that network operators should implement

v Technology-neutral baseline for global adoption

Page 5: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

5

Good MANRS

1.  Filtering – Prevent propagation of incorrect routing information.

2.  Anti-spoofing – Prevent traffic with spoofed source IP addresses.

3.  Coordination – Facilitate global operational communication and coordination between network operators.

4.  Global Validation – Facilitate validation of routing information on a global scale.

Page 6: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

6

MANRS participants today

Page 7: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

7

MANRS is not (only) a document – it is a commitment

1)  The company supports the Principles and implements at

least one of the Actions for the majority of its

infrastructure.

2)  The company becomes a Participant of MANRS, helping

to maintain and improve the document and to promote

MANRS objectives

Page 8: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

8

Why Should My Company Join?

Ø Because routing security is a sum of all contributions

Ø Because this is a way to demonstrate a new baseline

Ø Because a community has gravity that can attract others

Page 9: Internet Society - ENOG · 2016-08-22 · Good MANRS 1. Filtering – Prevent propagation of incorrect routing information. 2. Anti-spoofing – Prevent traffic with spoofed source

9

Maarit Palovirta ([email protected])

@European Regional Bureau

9

Thank you for your attention!