Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Adding A New Layer Of Security To The Global Internet
Articles

Adding A New Layer Of Security To The Global Internet

ISBuzz TeamBy ISBuzz TeamJuly 7, 2020Updated:March 9, 20235 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Ethernet cable with fiber optic background
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

As internet traffic continues to surge, Adam Davenport, director of interconnection strategy at GTT, explores the steps that must be taken to better protect consumers and businesses against route leaks and hijacks.

Throughout the COVID-19 pandemic, more and more people have relied on the internet to stay connected while keeping their distance. As a result, internet traffic has surged by around 30% since March. Putting that into context, it’s a volume of growth we’d typically expect for an entire year. 

Managing this explosion in traffic and transporting it throughout the world without compromising delivery speeds or the user experience is a big challenge. It’s a challenge that Tier 1 operators like GTT — which make up the core of the world’s internet — take on every day. However, another issue that is equally as important but is talked about less often is the challenge to ensure the internet is equipped with more robust security measures for the websites and cloud applications so many of us rely on every day. 

The threats to web traffic

Internet traffic “hops” from point to point across the autonomous systems that span the globe. IP addresses, similar to real-life addresses, are used to identify the thing that you’re connecting to it. This could be the router in your home, a blog site or your favorite online retailer. Traditionally, the routes a network is able to announce to the global Internet are protected by filters that are applied by their upstream providers.  These filters are generated from entries in the Internet Routing Registry (IRR), a database of registered internet routes. However, because anyone can create a registry entry for absolutely anything without any sort of verification or validation, the system is open to abuse.  

This lack of validation means that bad actors can create IRR entries for IP space that they are not authorized to use, leading to route leaks and hijacks. For instance, a bad actor wanting to intercept online credit card or cryptocurrency transactions could, in theory, register the IP prefixes of the intended target into IRR and then announce those IP blocks to their upstream providers, who accept them without any additional authorization or validation. This scenario would allow that bad actor to hijack all traffic destined to the IP address space of the legitimate owner for as long as the announcement was active. Additionally, unintended configuration issues can occur. It’s possible for a network operator to make a typo in an IP block when creating an IRR entry and accompanying network announcement.  When this occurs and is accepted and propagated by upstream providers, it can render the legitimate operator and sites associated with the IP space in question completely inoperable until the error is identified and corrected.

Securing global internet routing systems

With more people than ever reliant on the internet, developing new ways to better protect both consumers and businesses is essential. One such initiative is the implementation of a new verification system for IP addresses, called Resource Public Key Infrastructure (RPKI), that lets people and organizations who own one or more IP addresses officially register the address space as theirs and theirs alone. It has the added benefit of requiring that anyone registering an IP address block be properly authorized by one of the five Regional Internet Registries (RIRs), the organizations that manage and assign IP addresses. 

Having an official register of who owns which IP addresses provides an additional validation check, making it much harder for criminals to imitate, or “spoof,” those addresses and redirect the traffic to a fake look-alike site. Having this level of validation allows network operators to explicitly reject any IP announcement that is invalid in RPKI from their external neighbors.

Making the internet safer and more reliable is an ongoing mission for all IP network providers who ensure the huge volume of traffic on the internet can travel securely around the globe. GTT is one of the first large-scale global Tier 1 providers to deploy RPKI-based route validation across its entire global internet backbone. So if a client’s IP route is covered by an RPKI Route Origin Authorization (ROA) record, that client can be assured that their internet traffic is fully secure throughout GTT’s entire global network footprint.

Taking the next step

The availability of RPKI is an important milestone on the path to creating a safer internet. All businesses that own IP addresses can now take the next step to secure their services by becoming properly authorized at the RIR level in order to create an RPKI ROA record. However, organizations will still need to carry out due diligence checks. If they adopt an online hosted service from someone who owns IP address spaces, such as a blog or website service, then they need to ensure this service registers their address space with the appropriate system to help make the user experience more secure. 

As the world’s population becomes more and more reliant on the internet, network operators are responding collectively to the challenge of making the internet safer and more reliable, but there is still a long way to go. Implementing RPKI is an important step in the right direction and will help add an extra layer of protection and security to our ever-increasing digital world. 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read

Enhance Your Digital Crime and Security Practices Today

March 28, 20249 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}