Saatja: ria <
[email protected]>
Saaja: ria
Teema: RIA ohuhinnang: marsruutimisprotokoll BGP
Tere!
Saadame teile kui autonoomset süsteemi omavale asutusele Riigi Infosüsteemi Ameti ohuhinnangu marsruutimisprotokolli BGP turvanõrkuste kohta, samuti soovitused olukorra parandamiseks.
Koostasime selle tulenevalt hiljutistest intsidentidest ja CERT-EE-le laekunud infost, mille kohaselt on BGP nõrkusi ära kasutades kaaperdatud ka Eesti sideteenuste pakkujate IP-aadresse. Nende intsidentide üheks juurpõhjuseks on tõsiasi, et Eesti asutused paiknevad BGP turvamisel Euroopa Liidu liikmesriikidest viimaste seas.
Ohuhinnangu ja soovitused, kuidas muuta BGP turvalisemaks, leiate SIIT <https://www.ria.ee/sites/default/files/ria_ohuhinnang_bgp_est.pdf> .
Lugupidamisega
Lauri Aasmann
Peadirektori asetäitja küberturvalisuse alal
Riigi Infosüsteemi Amet
Pärnu maantee 139a, Tallinn 15169
Telefon: +372 663 0200
E-post:
[email protected]
--------------------
Dear Madam/Sir
As an owner of an autonomous system you receive a threat assessment on the routing protocol BGP (Border Gateway Protocol), by the The Estonian Information SystemAuthority (RIA), which comes with some recommendations on how to tackle the existing threats.
We compiled the assessment due to recent incidents and information received by CERT-EE about some IP-addresses of Estonian internet service providers having been also hijacked due to the weakness of the BGP. In addition, Estonian entities and companies are among the last in the European Union Member States in securing BGP.
The English version of RIA’s threat assessment and recommendations how to make BGP more secure, can be downloaded HERE <https://www.ria.ee/sites/default/files/ria_ohuhinnang_bgp_en.pdf> .
Kind regards,
Lauri Aasmann
Director of Cyber Security
Estonian Information System Authority (RIA)
Pärnu maantee 139a, Tallinn 15169
Phone: +372 663 0200
E-mail:
[email protected]