Cybersecurity Policy Report, FCC Seeks Input on Boosting BGP Security, (Jun 6, 2024)
Organizations Mentioned:USTelecom

By Lynn Stanton
The FCC today unanimously proposed requiring all broadband Internet access service providers to develop risk management plans to address Border Gateway Protocol (BGP) security vulnerabilities and requiring the nine largest broadband providers to file those plans confidentially with the FCC, along with quarterly data on implementation progress that would be available to the public.
“These plans would detail their progress and plans for implementing BGP security measures that utilize the Resource Public Key Infrastructure (RPKI), a critical component of BGP security,” the FCC said in a press release.
If the providers meet a security threshold, they would not have to file subsequent detailed plans.
Smaller providers would have to make their plans available to the FCC upon request.
BGP is used for routing traffic on the Internet, and security vulnerabilities enable traffic to be “hijacked” and delivered to entities that the sender did not intend.
“BGP’s initial decades-old design, which remains widely deployed today, does not include intrinsic security features to ensure trust in the information that is relied upon to exchange traffic among independently managed networks on the internet. BGP national security experts have raised concerns that a bad network actor may deliberately falsify BGP reachability information to redirect traffic. These ‘BGP hijacks’ can expose Americans’ personal information; enable theft, extortion, and state-level espionage; and disrupt services upon which the public or critical infrastructure sectors rely,” the FCC said.
The notice of proposed rulemaking (NPRM) adopted in PS docket 24-146 and 22-90 at the FCC’s meeting today seeks comment on the planning and reporting proposals “and other measures related to implementing RPKI-based security. In taking today’s action, the Commission recognized the efforts of multiple stakeholders over the past twenty years to address BGP vulnerabilities but noted that more work needs to be done to secure internet routing, which is critical to public safety and national security,” the FCC added.
In presenting the item at the meeting, Bradley Rosen, an attorney adviser in the Cybersecurity and Communications Reliability Division of the FCC’s Wireline Competition Bureau, said that the item seeks input on whether the FCC should establish timetables for RPKI implementation.
In remarks at the meeting, Commissioner Brendan Carr praised the NPRM for focusing on reporting rather than “substantive conduct-style regulations” and for seeking comment on ways to pursue “additional flexibility” on reporting requirements.
Commissioner Geoffrey Starks, who participated in the meeting remotely, said, “Border Gateway Protocol is the mechanism that enables our Internet service providers (ISPs) to route traffic throughout the variety of networks that, when combined, make up the Internet. I’ve been focused on this since 2022, when I sat down with a group of the largest ISPs in America to discuss the challenges surrounding Internet routing.”
He added that “we’ve seen a number of examples of attacks. YouTube was rendered inaccessible for much of the world after Pakistan attempted to block access to it within its borders by modifying YouTube’s BGP routes. Russia took advantage of BGP vulnerabilities to limit access to Twitter as part of its invasion of Ukraine. And China Telecom misdirected 15% of the world’s Internet traffic, and routed domestic U.S. Internet traffic through China, by hijacking BGP.”
In his written statement, Commissioner Starks said, “I thank the Chairwoman for her ongoing leadership in securing Internet routing, and for accepting my edits to make sure we ask questions about how our efforts can promote accountability among stakeholders, support the development of open standard settings solutions, such as RPKI, understand how network architecture plays into BGP security and RPKI deployment, and ensure that our efforts promote risk-based routing security among ISPs.”
Commissioner Nathan Simington said that the NPRM demonstrates the extent to which the agency “has already been forced to consider matters far outside the traditional remand of the Commission,” and he predicted that “this trend” of intergovernmental planning and the agency’s role in software issues “to accelerate.”
Commissioner Anna Gomez noted that security was not the focus of those who initially developed Internet protocols. Now that “we are more fully aware of these security vulnerabilities, the item we adopt today is about making communication routes more secure.”
In her written statement, Chairwoman Jessica Rosenworcel said, “I want to thank the Cybersecurity and Infrastructure Security Agency at the Department of Homeland Security for working with my office and jointly hosting a BGP public forum to discuss this problem. I also want to thank the Department of Defense and Department of Justice for publicly disclosing in our record that China Telecom used BGP vulnerabilities to misroute United States internet traffic on at least six occasions. These ‘BGP hijacks’ can expose personal information, enable theft, extortion, and state-level espionage. They can also disrupt sensitive transactions that require security, like those in the financial sector.”
She added, “Now for all of these reasons, today we begin a rulemaking to help make our internet routing more secure. We propose that all providers of broadband internet access service prepare and update confidential BGP security risk management plans. These plans would describe and attest to their efforts to follow existing best practices with respect to Route Origin Authorizations and Route Origin Validation using the Resource Public Key Infrastructure. In addition, we propose quarterly reporting for the largest providers to ensure we are making progress addressing this well-known vulnerability.”
In a statement, USTelecom said, “USTelecom is working shoulder-to-shoulder with multiple government agencies on a risk-based, collaborative effort to advance routing security across the global digital ecosystem. We will continue working with the FCC to ensure this rulemaking does not lead to rigid, top-down regulations that undermine that important partnership.”
MainStory: TopStory DataSecurity