The White House Office of the National Cyber Director (ONCD) released the Roadmap to Enhancing Internet Routing Security report earlier this month. 

The Border Gateway Protocol (BGP) is used to navigate the internet. Problems, such as misdirection of traffic, loss of service, and theft of service are possible if the routing information used by the BGP is incorrect.

The roadmap seeks to confront this challenge. A key step to security is the creation of Route Origin Authorizations (ROAs), which are cryptographic verifications that the destination is correct. 

Other key elements discussed in the roadmap are Route Original Validation (ensuring matches between BGP filtering announcements and ROAs and filtering of invalid BGPs) and Mutually Agreed Norms for Routing Security (MANRS) that recommend baseline actions every network can implement affordably.

The ONCD developed the recommendations in partnership with the National Institute of Standards and Technology (NIST), the Department of Justice (DOJ), the Federal Communications Commission (FCC), the Cybersecurity and Infrastructure Security Agency (CISA), and other agencies.

“The U.S. Government is committed to working closely with the multistakeholder community to identify and implement best practices for BGP security and other Internet governance challenges,” said Robert Cannon, the Senior Telecommunications Policy Analyst for the National Telecommunications and Information Administration (NTIA),  in a blog post.

“Collaboration with stakeholders makes us all stronger when tackling what the National Cybersecurity Strategy calls “pervasive concerns” like BGP security.”

Other contributors to the initiative included The American Registry for Internet Numbers (ARIN), The Internet Society, Mutually Agreed Norms for Routing Security (MANRS), The Global Cyber Alliance, Internet2 Routing Integrity, Network Startup Resource Center (RouteViews), Center for Applied Internet Data Analysis, the RoVista project at Virginia Tech, and others.