@techreport{liu-sidrops-community-authentication-01, number = {draft-liu-sidrops-community-authentication-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-liu-sidrops-community-authentication/01/}, author = {Yunhao Liu and Jessie Hui Wang and Yangyang Wang and Mingwei Xu}, title = {{BGP Community-based Attacks and Community Origin Authentication}}, pagetotal = 25, year = 2024, month = mar, day = 24, abstract = {BGP community usage has continued to increase during the past decade. Unfortunately, while BGP community is a seemingly innocuous feature, it can be used to influence routing in unintended ways. Existing defense mechanisms are insufficient to prevent community-based attacks. This document describes some of the scenarios that may be used to launch these attacks and make recommendations on practices that may defend them. In particular, this document proposes SecCommunity, an extension to the Border Gateway Protocol (BGP) that can authenticate the ASes who added action community values on the announcements.}, }