Uploaded February 2026 | Updated September 2026, 1 week ago
Abstract
As Route Origin Validation (ROV) adoption grows, measuring who deploys it—and how they rely on upstreams—has become harder. Traditional control- and data-plane methods often blur the line between local enforcement and inherited protection, and visibility shrinks as more networks drop invalid routes. We present our measurement framework that dynamically serves customized ROAs from controlled publication points to target specific Relying Party (RP) servers, selectively invalidating prefixes to one RP at a time. Paired with large-scale active probing, we reveal direct dependencies between 21,827 ASes, their transit providers, and RP infrastructure.
We find 1,127 ASes self-deploy ROV, while 1,815 rely entirely on upstream filtering—69.6% of these “protected” ASes remain vulnerable to local hijacks. Over half of ROV-deploying ASes depend on a single RP server, and router enforcement lags ROA updates by ~37 minutes. Simulations show that enabling ROV in the top 100 ASes protects 27.6% of networks, but disabling it in Tier-1s exposes 23.8% to hijacks. We’ll discuss these systemic risks, why collateral protection can be misleading, and how resilient RP configurations can strengthen routing security. Tools and datasets are open-sourced to support community measurement and mitigation efforts.
Tijay Chung:
Taejoong (Tijay) Chung is an Associate Professor at the Computer Science department at Virginia Tech. His work focuses on Internet security and measurement. He received the NSF CAREER Award (2024) and NSF CRII Award (2019). He also received Outstanding New Assistant Professor at the College of Engineering, Virginia Tech (2024). He was a Mentor at Mutually Agreed Norms for Routing Security (MANRS), Internet Society in 2023. He received the ACM CCS Best Paper Honorable Mention Award (2022), IRTF Applied Networking Research Prize (2019), ACM IMC Distinguished Paper Award (2019), and USENIX Security Distinguished Paper Award (2017).
nanog.org/events/nanog-96/content/5544
Abstract
As Route Origin Validation (ROV) adoption grows, measuring who deploys it—and how they rely on upstreams—has become harder. Traditional control- and data-plane methods often blur the line between local enforcement and inherited protection, and visibility shrinks as more networks drop invalid routes. We present our measurement framework that dynamically serves customized ROAs from controlled publication points to target specific Relying Party (RP) servers, selectively invalidating prefixes to one RP at a time. Paired with large-scale active probing, we reveal direct dependencies between 21,827 ASes, their transit providers, and RP infrastructure.
We find 1,127 ASes self-deploy ROV, while 1,815 rely entirely on upstream filtering—69.6% of these “protected” ASes remain vulnerable to local hijacks. Over half of ROV-deploying ASes depend on a single RP server, and router enforcement lags ROA updates by ~37 minutes. Simulations show that enabling ROV in the top 100 ASes protects 27.6% of networks, but disabling it in Tier-1s exposes 23.8% to hijacks. We’ll discuss these systemic risks, why collateral protection can be misleading, and how resilient RP configurations can strengthen routing security. Tools and datasets are open-sourced to support community measurement and mitigation efforts.
Tijay Chung:
Taejoong (Tijay) Chung is an Associate Professor at the Computer Science department at Virginia Tech. His work focuses on Internet security and measurement. He received the NSF CAREER Award (2024) and NSF CRII Award (2019). He also received Outstanding New Assistant Professor at the College of Engineering, Virginia Tech (2024). He was a Mentor at Mutually Agreed Norms for Routing Security (MANRS), Internet Society in 2023. He received the ACM CCS Best Paper Honorable Mention Award (2022), IRTF Applied Networking Research Prize (2019), ACM IMC Distinguished Paper Award (2019), and USENIX Security Distinguished Paper Award (2017).
nanog.org/events/nanog-96/content/5544










