FINDING · EVALUATION
Router-level mapping of the 30 key ASes reveals that 11,709 individual routers must be replaced with Decoy Routers (non-censorious ASes only), at a hardware cost exceeding $10.3 billion USD. Individual large ASes require hundreds to over 1,600 router replacements (e.g., AS3356 needs 576, AS209 Quest Communications needs 1,662). Even targeting the weakest adversary studied, Syria (containable by 3 ASes at AS level), requires 1,117 DRs.
From 2017-gosain-devil-s — The Devil's in The Details: Placing Decoy Routers in the Internet · §5.2, §6.4, Table 3–4 · 2017 · ACSAC
Implications
- Any practical DR deployment must budget for router-level deployment costs — not just AS-operator agreements — since even a 3-AS solution for a weak adversary requires over 1,000 hardware replacements.
- DR architectures that minimize interception points per AS (e.g., operating only at a small set of heavy-hitter edge routers rather than all edge routers) could substantially reduce the capital cost identified here.
Tags
Extracted by claude-sonnet-4-6 — review before relying.