SlideShare a Scribd company logo
1 of 30
Download to read offline
สวัสดี🙏
Lia Hestina
Senior Project Coordinator
RIPE NCC
Before Incidents Occur with RIPE Atlas and RIS
Minimising Impact
Lia Hestina | APRICOT 2024 | Bangkok
Lia Hestina | APRICOT 2024 | Bangkok 3
The world outside is pretty dark…
Lia Hestina | APRICOT 2024 | Bangkok
How do you minimise the impact?
Action
Gear up
Escape
Lia Hestina | APRICOT 2024 | Bangkok
How do you minimise impact?
• Strategic Deployment:
• Install RIPE Atlas probes & anchor
strategically
• Peer with RIS (Routing Information Services)
• Continuous Monitoring: Conduct ongoing
measurements
• Abnormality Alerts:
• Set up alerts for deviations from normal
measurements
• Detect route hijacks
Gear up
• Anomaly Detection: Identify network
issues swiftly.
• Latency Assurance: Debug and
maintain low latency.
• Performance Showcase: Impress
customers with network performance
Action
Lia Hestina | APRICOT 2024 | Bangkok
RIPE Atlas
• RIPE Atlas is a global active
measurements platform, funded
by RIPE NCC members and
sponsors
• The goal: To view your Internet
reachability from outside your
network
• Probes hosted by volunteers,
using a credits system
• Data is publicly available
atlas.ripe.net
6
Lia Hestina | APRICOT 2024 | Bangkok 7
Run RIPE Atlas tests More than 12000 probes connected globally
Lia Hestina | APRICOT 2024 | Bangkok
RIPE Atlas
Types of measurements
8
PING
TRACEROUTE
DNS
HTTP (anchors)
SSL/TLS
NTP
GUI
API
CLI TOOL
Accessible via
Lia Hestina | APRICOT 2024 | Bangkok
Security and Privacy
9
Trust Material (regular server address, keys)
NO open Ports; initiate connection; NAT is
OK
Don’t listen to local traffic
No snooping
Measurements
No passive measurements
SSH connections from probe to
server
Initiated by Probes
Code of measurements publicly
available
Probes
Lia Hestina | APRICOT 2024 | Bangkok
Types of Probes
10
Hardware . Software .
Installation Physical Device Software base, user machine or VMs
Uptime 24/7 Same as the device it’s installed on
Measurements Same Same
https://labs.ripe.net/author/stephen_strowes/reviewing-ripe-atlas-software-probes/
Lia Hestina | APRICOT 2024 | Bangkok
What is RIS?
• RIS is a routing data collection platform
• Collecting BGP data since 1999
• Up-to-date routing information, as
opposed to information in databases and
routing registries, such as:
- What is being announced
- Which prefixes are seen and where
- Which prefixes are not seen
11
23 collectors
1377 global peers
THANK YOU TO OUR COMMUNITY
Lia Hestina | APRICOT 2024 | Bangkok
How can RIS help network operators?
• Is your prefix getting announced?
- RIS Live (https://ris-live.ripe.net/)
- RIPEstat (Inforedes)
• Tools developed by others allow you to set an alert
- Try out BGP Alerter (powered by RIS Live)
- PacketVis https://packetvis.com/
12
Lia Hestina | APRICOT 2024 | Bangkok
• High latency = impatient gamers
• Gamers from different networks
• Realtime application, unpredictable
13
Some Problems
Kunang
Online gaming company
Runs own LAN
Users from around the world
Lia Hestina | APRICOT 2024 | Bangkok 14
1. Strategic Deployment: Install RIPE Atlas (software)
ASN Name
131445 3AIS3G-2100-AS-AP
17552 TRUEONLINE-AS-AP
133481 AIS-Fibre-AS-AP
45629 JASTEL-NETWORK-TH-AP
24378 ENGTAC-AS-TH-AP
132061 Realmove-as-ap
23969 TOT-NET
132618 REALFUTURE-AS-AP
Gear up
Lia Hestina | APRICOT 2024 | Bangkok 15
ASN 12654
Traffic profile mostly balanced
Traffic Volume 0-20Mbps
Peering Policy Selective
Peering Locations
(IX or POP)
RRCs at 23 locations globally: https://www.ripe.net/
analyse/internet-measurements/routing-information-
service-ris/ris-peering-policy
PeeringDB entry as12654.peeringdb.com
Contact information ris-peering@ripe.net
Michela Galante: mgalante@ripe.net
Marco Giuliani: mgiuliani@ripe.net
Jelena Cosic: jcosic@ripe.net
Gear up
1. Strategic Deployment: Peer with RIS
Lia Hestina | APRICOT 2024 | Bangkok 16
2. Monitor your network performance
High latency
Identified
Lower latency after debugging
Talk to your peers, ISP or any that can help improve RTT
Gear up
Lia Hestina | APRICOT 2024 | Bangkok 17
3. Set up alerts for any abnormal results
Gear up
Lia Hestina | APRICOT 2024 | Bangkok 18
• Anomaly Detection: Identify network
issues swiftly.
• Latency Assurance: Debug and
maintain low latency.
• Performance Showcase: Impress
customers with network performance
Action
Service desks ♥
RIPE Atlas GUI
To validate findings
For your staff
Control & Flexibility
Repeat tests as much as you need!
For YOU
Improve Performance
Shorter path is selected, better
latency, reliability & security
For your clients
A view into
Thailand and South East Asia
Lia Hestina | APRICOT 2024 | Bangkok
Probes in
South East Asia
20
Country Code Probe Anchor
BN 3
MM 2
KH 2 1
TL 1
ID 92 12
LA 1
MY 27 3
PH 54 4
SG 129 29
TH 29 2
VN 8 1
Lia Hestina | APRICOT 2024 | Bangkok 21
Measurements in 2023 with Thai probes
638,089 UDMs
350,951 created by IPmap
Tools for Network Operators
(Prototype)
Lia Hestina | APRICOT 2024 | Bangkok 23
https://observablehq.com/@ripencc/atlas-latency-worldmap
Latency IX-225
Thailand
MinRTT
Lia Hestina | APRICOT 2024 | Bangkok 24
MinRTT
Your network neighbourhood as seen through RIPE Atlas
Try your probe here
https://observablehq.com/
@ripencc/atlas-probe-
neighbourhood?
Are these networks with
high latency important to you?
Lia Hestina | APRICOT 2024 | Bangkok
IXP Country JEDI
Keep your traffic
in Thailand LOCAL
25
South Africa
AS9299
https://jedi.ripe.net/latest/PH/ixpcountry/index.html?ASNS=all&ipv=v4
Lia Hestina | APRICOT 2024 | Bangkok
More reasons to love RIPE Atlas
26
12,000 Probes
Safe and Secure
Trusted Source
Open Data
Community Driven
Fair Use/
NON Monetary
Global Coverage
Regular third-party security review
Non-profit organisation
Volunteers: End Users
Measurement results open to all
From the community & RIPE NCC
for the community
Lia Hestina | APRICOT 2024 | Bangkok
What do you do now?
Redeem This Voucher
Sawasdee24
27
Create a RIPE NCC Access ACCOUNT
1
INSTALL RIPE Atlas probe strategically
2
PEER with RIS
3
Start testing, MONITOR your network performance
4
Got a disconnected probe? Reconnect!
5
Lia Hestina | APRICOT 2024 | Bangkok
Let’s talk…
28
Tell us what is
important to you!
We can develop
new prototypes!
Questions ?
lhestina@ripe.net
atlas@ripe.net
Lia Hestina | APRICOT 2024 | Bangkok
Use Cases on RIPE Labs
30
Detecting DNS root manipulation
https://labs.ripe.net/author/qasim-lone/
detecting-dns-root-manipulation/
DNS vulnerability, configuration
errors that can cause DDoS
https://labs.ripe.net/author/giovane_moura/
dns-vulnerability-configuration-errors-that-can-
cause-ddos/
The Kazakhstan outage
as seen from RIPE Atlas
https://labs.ripe.net/author/emileaben/the-
kazakhstan-outage-as-seen-from-ripe-atlas/
A distributed view of the Internet
https://labs.ripe.net/author/alun_davies/ripe-
atlas-a-distributed-view-of-the-internet/

More Related Content

Similar to LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS

RIPE Atlas Tools for Operators and IXPs
RIPE Atlas Tools for Operators and IXPsRIPE Atlas Tools for Operators and IXPs
RIPE Atlas Tools for Operators and IXPsAPNIC
 
PhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTPhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTAPNIC
 
VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools APNIC
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC
 
Internet number resources - what's new?
Internet number resources - what's new?Internet number resources - what's new?
Internet number resources - what's new?APNIC
 
RIPEstat, RIPE Atlas and the new DNSMON
RIPEstat, RIPE Atlas and the new DNSMONRIPEstat, RIPE Atlas and the new DNSMON
RIPEstat, RIPE Atlas and the new DNSMONRIPE NCC
 
IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?apnic_slides
 
IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013APNIC
 
Government
Government Government
Government APNIC
 
Government Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkagesGovernment Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkagesAPNIC
 
PLNOG 31 Alena Muravska 2023.pdf
PLNOG 31 Alena Muravska 2023.pdfPLNOG 31 Alena Muravska 2023.pdf
PLNOG 31 Alena Muravska 2023.pdfRIPE NCC
 
RIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for ResearchersRIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for ResearchersRIPE NCC
 
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...Deploy360 Programme (Internet Society)
 
SGNOG2 - APNIC Updates
SGNOG2 - APNIC UpdatesSGNOG2 - APNIC Updates
SGNOG2 - APNIC UpdatesAPNIC
 
PITA 22: Addressing interconnection and security in the Pacific
PITA 22: Addressing interconnection and security in the PacificPITA 22: Addressing interconnection and security in the Pacific
PITA 22: Addressing interconnection and security in the PacificAPNIC
 
WINS: Peering and IXPs
WINS: Peering and IXPsWINS: Peering and IXPs
WINS: Peering and IXPsAPNIC
 
APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014APNIC
 

Similar to LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS (20)

RIPE Atlas Tools for Operators and IXPs
RIPE Atlas Tools for Operators and IXPsRIPE Atlas Tools for Operators and IXPs
RIPE Atlas Tools for Operators and IXPs
 
PhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRTPhNOG 2020: Securing your resources with RPKI and IRT
PhNOG 2020: Securing your resources with RPKI and IRT
 
VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools VINX-NOG 2022: An update on IPv6, RPKI and tools
VINX-NOG 2022: An update on IPv6, RPKI and tools
 
Update-IR-IX
Update-IR-IXUpdate-IR-IX
Update-IR-IX
 
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
APNIC Update and RIR Policies for ccTLDs, presented at APTLD 85
 
Internet number resources - what's new?
Internet number resources - what's new?Internet number resources - what's new?
Internet number resources - what's new?
 
RIPEstat, RIPE Atlas and the new DNSMON
RIPEstat, RIPE Atlas and the new DNSMONRIPEstat, RIPE Atlas and the new DNSMON
RIPEstat, RIPE Atlas and the new DNSMON
 
CATNIX: Desafíos y experiencia
CATNIX: Desafíos y experienciaCATNIX: Desafíos y experiencia
CATNIX: Desafíos y experiencia
 
IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?IPv6 Deployment: Why and Why not?
IPv6 Deployment: Why and Why not?
 
IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013
 
Government
Government Government
Government
 
Government Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkagesGovernment Policy and IPv6 Adoption - Strategic linkages
Government Policy and IPv6 Adoption - Strategic linkages
 
09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono09 (IDNOG01) Introduction about APNIC by Wita Laksono
09 (IDNOG01) Introduction about APNIC by Wita Laksono
 
PLNOG 31 Alena Muravska 2023.pdf
PLNOG 31 Alena Muravska 2023.pdfPLNOG 31 Alena Muravska 2023.pdf
PLNOG 31 Alena Muravska 2023.pdf
 
RIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for ResearchersRIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for Researchers
 
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
ION Costa Rica - Two Years of Good MANRS: Improving Global Routing Security &...
 
SGNOG2 - APNIC Updates
SGNOG2 - APNIC UpdatesSGNOG2 - APNIC Updates
SGNOG2 - APNIC Updates
 
PITA 22: Addressing interconnection and security in the Pacific
PITA 22: Addressing interconnection and security in the PacificPITA 22: Addressing interconnection and security in the Pacific
PITA 22: Addressing interconnection and security in the Pacific
 
WINS: Peering and IXPs
WINS: Peering and IXPsWINS: Peering and IXPs
WINS: Peering and IXPs
 
APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014APNIC Regional Update: PacINET 2014
APNIC Regional Update: PacINET 2014
 

More from RIPE NCC

Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryRIPE NCC
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionRIPE NCC
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in TechRIPE NCC
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfRIPE NCC
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopRIPE NCC
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfRIPE NCC
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfRIPE NCC
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsRIPE NCC
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing SecurityRIPE NCC
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfRIPE NCC
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasRIPE NCC
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasRIPE NCC
 
111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure111 views of Swiss Internet Infrastructure
111 views of Swiss Internet InfrastructureRIPE NCC
 
The RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenThe RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenRIPE NCC
 
IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)RIPE NCC
 
Finland Internet Country Report
Finland Internet Country ReportFinland Internet Country Report
Finland Internet Country ReportRIPE NCC
 
Moldova Country Report
Moldova Country ReportMoldova Country Report
Moldova Country ReportRIPE NCC
 
Routing Security, Another Elephant in the Room
Routing Security, Another Elephant in the RoomRouting Security, Another Elephant in the Room
Routing Security, Another Elephant in the RoomRIPE NCC
 

More from RIPE NCC (20)

Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet Registry
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate Action
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in Tech
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement Tools
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the Baltics
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing Security
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement Services
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure111 views of Swiss Internet Infrastructure
111 views of Swiss Internet Infrastructure
 
The RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in SwedenThe RIPE NCC’s View of IPv6 in Sweden
The RIPE NCC’s View of IPv6 in Sweden
 
IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)IPv6 in the Nordics (and why it’s important)
IPv6 in the Nordics (and why it’s important)
 
Finland Internet Country Report
Finland Internet Country ReportFinland Internet Country Report
Finland Internet Country Report
 
Moldova Country Report
Moldova Country ReportMoldova Country Report
Moldova Country Report
 
Routing Security, Another Elephant in the Room
Routing Security, Another Elephant in the RoomRouting Security, Another Elephant in the Room
Routing Security, Another Elephant in the Room
 

Recently uploaded

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制pxcywzqs
 
一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样
一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样
一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样AS
 
一比一原版英国格林多大学毕业证如何办理
一比一原版英国格林多大学毕业证如何办理一比一原版英国格林多大学毕业证如何办理
一比一原版英国格林多大学毕业证如何办理AS
 
一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书
一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书
一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书c6eb683559b3
 
一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理SS
 
Research Assignment - NIST SP800 [172 A] - Presentation.pptx
Research Assignment - NIST SP800 [172 A] - Presentation.pptxResearch Assignment - NIST SP800 [172 A] - Presentation.pptx
Research Assignment - NIST SP800 [172 A] - Presentation.pptxi191686
 
一比一原版美国北卡罗莱纳大学毕业证如何办理
一比一原版美国北卡罗莱纳大学毕业证如何办理一比一原版美国北卡罗莱纳大学毕业证如何办理
一比一原版美国北卡罗莱纳大学毕业证如何办理A
 
APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0
APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0
APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0APNIC
 
一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理F
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样ayvbos
 
Loker Pemandu Lagu LC Semarang 085746015303
Loker Pemandu Lagu LC Semarang 085746015303Loker Pemandu Lagu LC Semarang 085746015303
Loker Pemandu Lagu LC Semarang 085746015303Dewi Agency
 
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformonhackersuli
 
如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证
如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证
如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证hfkmxufye
 
A LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptx
A LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptxA LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptx
A LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptxthinamazinyo
 
APNIC Updates presented by Paul Wilson at CaribNOG 27
APNIC Updates presented by Paul Wilson at  CaribNOG 27APNIC Updates presented by Paul Wilson at  CaribNOG 27
APNIC Updates presented by Paul Wilson at CaribNOG 27APNIC
 
Lowongan Kerja LC Yogyakarta Terbaru 085746015303
Lowongan Kerja LC Yogyakarta Terbaru 085746015303Lowongan Kerja LC Yogyakarta Terbaru 085746015303
Lowongan Kerja LC Yogyakarta Terbaru 085746015303Dewi Agency
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdfMatthew Sinclair
 
一比一原版犹他大学毕业证如何办理
一比一原版犹他大学毕业证如何办理一比一原版犹他大学毕业证如何办理
一比一原版犹他大学毕业证如何办理F
 
一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样
一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样
一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样AS
 

Recently uploaded (20)

APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
 
一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样
一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样
一比一原版(Polytechnic毕业证书)新加坡理工学院毕业证原件一模一样
 
一比一原版英国格林多大学毕业证如何办理
一比一原版英国格林多大学毕业证如何办理一比一原版英国格林多大学毕业证如何办理
一比一原版英国格林多大学毕业证如何办理
 
一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书
一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书
一比一原版(NYU毕业证书)美国纽约大学毕业证学位证书
 
一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理
 
Research Assignment - NIST SP800 [172 A] - Presentation.pptx
Research Assignment - NIST SP800 [172 A] - Presentation.pptxResearch Assignment - NIST SP800 [172 A] - Presentation.pptx
Research Assignment - NIST SP800 [172 A] - Presentation.pptx
 
一比一原版美国北卡罗莱纳大学毕业证如何办理
一比一原版美国北卡罗莱纳大学毕业证如何办理一比一原版美国北卡罗莱纳大学毕业证如何办理
一比一原版美国北卡罗莱纳大学毕业证如何办理
 
APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0
APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0
APNIC Policy Roundup presented by Sunny Chendi at TWNOG 5.0
 
一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理一比一原版田纳西大学毕业证如何办理
一比一原版田纳西大学毕业证如何办理
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
 
Loker Pemandu Lagu LC Semarang 085746015303
Loker Pemandu Lagu LC Semarang 085746015303Loker Pemandu Lagu LC Semarang 085746015303
Loker Pemandu Lagu LC Semarang 085746015303
 
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
 
如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证
如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证
如何办理(UCLA毕业证)加州大学洛杉矶分校毕业证成绩单本科硕士学位证留信学历认证
 
A LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptx
A LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptxA LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptx
A LOOK INTO NETWORK TECHNOLOGIES MAINLY WAN.pptx
 
APNIC Updates presented by Paul Wilson at CaribNOG 27
APNIC Updates presented by Paul Wilson at  CaribNOG 27APNIC Updates presented by Paul Wilson at  CaribNOG 27
APNIC Updates presented by Paul Wilson at CaribNOG 27
 
Lowongan Kerja LC Yogyakarta Terbaru 085746015303
Lowongan Kerja LC Yogyakarta Terbaru 085746015303Lowongan Kerja LC Yogyakarta Terbaru 085746015303
Lowongan Kerja LC Yogyakarta Terbaru 085746015303
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
一比一原版犹他大学毕业证如何办理
一比一原版犹他大学毕业证如何办理一比一原版犹他大学毕业证如何办理
一比一原版犹他大学毕业证如何办理
 
一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样
一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样
一比一原版(毕业证书)新加坡南洋理工学院毕业证原件一模一样
 

LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS

  • 2. Before Incidents Occur with RIPE Atlas and RIS Minimising Impact Lia Hestina | APRICOT 2024 | Bangkok
  • 3. Lia Hestina | APRICOT 2024 | Bangkok 3 The world outside is pretty dark…
  • 4. Lia Hestina | APRICOT 2024 | Bangkok How do you minimise the impact? Action Gear up Escape
  • 5. Lia Hestina | APRICOT 2024 | Bangkok How do you minimise impact? • Strategic Deployment: • Install RIPE Atlas probes & anchor strategically • Peer with RIS (Routing Information Services) • Continuous Monitoring: Conduct ongoing measurements • Abnormality Alerts: • Set up alerts for deviations from normal measurements • Detect route hijacks Gear up • Anomaly Detection: Identify network issues swiftly. • Latency Assurance: Debug and maintain low latency. • Performance Showcase: Impress customers with network performance Action
  • 6. Lia Hestina | APRICOT 2024 | Bangkok RIPE Atlas • RIPE Atlas is a global active measurements platform, funded by RIPE NCC members and sponsors • The goal: To view your Internet reachability from outside your network • Probes hosted by volunteers, using a credits system • Data is publicly available atlas.ripe.net 6
  • 7. Lia Hestina | APRICOT 2024 | Bangkok 7 Run RIPE Atlas tests More than 12000 probes connected globally
  • 8. Lia Hestina | APRICOT 2024 | Bangkok RIPE Atlas Types of measurements 8 PING TRACEROUTE DNS HTTP (anchors) SSL/TLS NTP GUI API CLI TOOL Accessible via
  • 9. Lia Hestina | APRICOT 2024 | Bangkok Security and Privacy 9 Trust Material (regular server address, keys) NO open Ports; initiate connection; NAT is OK Don’t listen to local traffic No snooping Measurements No passive measurements SSH connections from probe to server Initiated by Probes Code of measurements publicly available Probes
  • 10. Lia Hestina | APRICOT 2024 | Bangkok Types of Probes 10 Hardware . Software . Installation Physical Device Software base, user machine or VMs Uptime 24/7 Same as the device it’s installed on Measurements Same Same https://labs.ripe.net/author/stephen_strowes/reviewing-ripe-atlas-software-probes/
  • 11. Lia Hestina | APRICOT 2024 | Bangkok What is RIS? • RIS is a routing data collection platform • Collecting BGP data since 1999 • Up-to-date routing information, as opposed to information in databases and routing registries, such as: - What is being announced - Which prefixes are seen and where - Which prefixes are not seen 11 23 collectors 1377 global peers THANK YOU TO OUR COMMUNITY
  • 12. Lia Hestina | APRICOT 2024 | Bangkok How can RIS help network operators? • Is your prefix getting announced? - RIS Live (https://ris-live.ripe.net/) - RIPEstat (Inforedes) • Tools developed by others allow you to set an alert - Try out BGP Alerter (powered by RIS Live) - PacketVis https://packetvis.com/ 12
  • 13. Lia Hestina | APRICOT 2024 | Bangkok • High latency = impatient gamers • Gamers from different networks • Realtime application, unpredictable 13 Some Problems Kunang Online gaming company Runs own LAN Users from around the world
  • 14. Lia Hestina | APRICOT 2024 | Bangkok 14 1. Strategic Deployment: Install RIPE Atlas (software) ASN Name 131445 3AIS3G-2100-AS-AP 17552 TRUEONLINE-AS-AP 133481 AIS-Fibre-AS-AP 45629 JASTEL-NETWORK-TH-AP 24378 ENGTAC-AS-TH-AP 132061 Realmove-as-ap 23969 TOT-NET 132618 REALFUTURE-AS-AP Gear up
  • 15. Lia Hestina | APRICOT 2024 | Bangkok 15 ASN 12654 Traffic profile mostly balanced Traffic Volume 0-20Mbps Peering Policy Selective Peering Locations (IX or POP) RRCs at 23 locations globally: https://www.ripe.net/ analyse/internet-measurements/routing-information- service-ris/ris-peering-policy PeeringDB entry as12654.peeringdb.com Contact information ris-peering@ripe.net Michela Galante: mgalante@ripe.net Marco Giuliani: mgiuliani@ripe.net Jelena Cosic: jcosic@ripe.net Gear up 1. Strategic Deployment: Peer with RIS
  • 16. Lia Hestina | APRICOT 2024 | Bangkok 16 2. Monitor your network performance High latency Identified Lower latency after debugging Talk to your peers, ISP or any that can help improve RTT Gear up
  • 17. Lia Hestina | APRICOT 2024 | Bangkok 17 3. Set up alerts for any abnormal results Gear up
  • 18. Lia Hestina | APRICOT 2024 | Bangkok 18 • Anomaly Detection: Identify network issues swiftly. • Latency Assurance: Debug and maintain low latency. • Performance Showcase: Impress customers with network performance Action Service desks ♥ RIPE Atlas GUI To validate findings For your staff Control & Flexibility Repeat tests as much as you need! For YOU Improve Performance Shorter path is selected, better latency, reliability & security For your clients
  • 19. A view into Thailand and South East Asia
  • 20. Lia Hestina | APRICOT 2024 | Bangkok Probes in South East Asia 20 Country Code Probe Anchor BN 3 MM 2 KH 2 1 TL 1 ID 92 12 LA 1 MY 27 3 PH 54 4 SG 129 29 TH 29 2 VN 8 1
  • 21. Lia Hestina | APRICOT 2024 | Bangkok 21 Measurements in 2023 with Thai probes 638,089 UDMs 350,951 created by IPmap
  • 22. Tools for Network Operators (Prototype)
  • 23. Lia Hestina | APRICOT 2024 | Bangkok 23 https://observablehq.com/@ripencc/atlas-latency-worldmap Latency IX-225 Thailand MinRTT
  • 24. Lia Hestina | APRICOT 2024 | Bangkok 24 MinRTT Your network neighbourhood as seen through RIPE Atlas Try your probe here https://observablehq.com/ @ripencc/atlas-probe- neighbourhood? Are these networks with high latency important to you?
  • 25. Lia Hestina | APRICOT 2024 | Bangkok IXP Country JEDI Keep your traffic in Thailand LOCAL 25 South Africa AS9299 https://jedi.ripe.net/latest/PH/ixpcountry/index.html?ASNS=all&ipv=v4
  • 26. Lia Hestina | APRICOT 2024 | Bangkok More reasons to love RIPE Atlas 26 12,000 Probes Safe and Secure Trusted Source Open Data Community Driven Fair Use/ NON Monetary Global Coverage Regular third-party security review Non-profit organisation Volunteers: End Users Measurement results open to all From the community & RIPE NCC for the community
  • 27. Lia Hestina | APRICOT 2024 | Bangkok What do you do now? Redeem This Voucher Sawasdee24 27 Create a RIPE NCC Access ACCOUNT 1 INSTALL RIPE Atlas probe strategically 2 PEER with RIS 3 Start testing, MONITOR your network performance 4 Got a disconnected probe? Reconnect! 5
  • 28. Lia Hestina | APRICOT 2024 | Bangkok Let’s talk… 28 Tell us what is important to you! We can develop new prototypes!
  • 30. Lia Hestina | APRICOT 2024 | Bangkok Use Cases on RIPE Labs 30 Detecting DNS root manipulation https://labs.ripe.net/author/qasim-lone/ detecting-dns-root-manipulation/ DNS vulnerability, configuration errors that can cause DDoS https://labs.ripe.net/author/giovane_moura/ dns-vulnerability-configuration-errors-that-can- cause-ddos/ The Kazakhstan outage as seen from RIPE Atlas https://labs.ripe.net/author/emileaben/the- kazakhstan-outage-as-seen-from-ripe-atlas/ A distributed view of the Internet https://labs.ripe.net/author/alun_davies/ripe- atlas-a-distributed-view-of-the-internet/