FINDING · DEFENSE

Through Internet-scale BGP simulation against China, downstream-only decoy routing (Waterfall) with a single decoy AS provides equivalent resistance to routing attacks as a traditional upstream decoy system (e.g., Telex) with 53 decoy ASes. This efficiency gain arises because censoring ISPs can selectively re-route upstream traffic per destination but must re-route all or none of downstream traffic through each provider AS, making downstream-only routing far more expensive to evade.

From 2017-nasr-waterfallThe Waterfall of Liberty: Decoy Routing Circumvention that Resists Routing Attacks · §4.1.1 · 2017 · Computer and Communications Security

Implications

Tags

censors
cn
techniques
bgp-hijack
defenses
decoy-routingtelex

Extracted by claude-sonnet-4-6 — review before relying.