Data-driven Policy Recommendations and Sector-specific Routing Security Analysis in Pakistan

In this post, I will explore a project I was involved in during my MANRS Ambassador role that analyzed the Internet routing security policies of three main sectors in Pakistan: Telecom-ISP, Financial, and Enterprise-Datacenter.

Our in-depth analysis examines compliance with Routing Information (IRR) and Resource Public Key Infrastructure (RPKI), identifying unique challenges and compliance levels across these sectors. The insights lead to sector-specific policy recommendations, underlining the necessity of data-driven strategies for enhancing digital security and connectivity in Pakistan.

This post highlights the importance of targeted policies in improving Internet reliability and security.

Understanding the Dataset

Our journey begins with a careful examination of the dataset. It encompasses various fields, including Autonomous System Numbers (ASNs), Holders, Sectors, and metrics related to routing information practices (IRR and RPKI).

Understanding the dataset’s structure was pivotal in selecting the most relevant columns for analysis. Thankfully, the MANRS Observatory dataset’s well-organized nature facilitated a smoother transition to the next stage of our analysis.

Categorizing Compliance – The Methodology

To align with the interests and concerns of relevant stakeholders, the 264 ASNs within Pakistan were strategically categorized into three distinct sectors. This approach ensured that policy recommendations were specifically tailored to address the unique needs of regulatory entities in each sector, thereby fostering compliance.

Telecom-ISP Sector: This sector includes ASN holders primarily engaged in telecommunications services, such as Internet Service Providers (ISPs), telecom operators, and network service providers. These entities are crucial in providing Internet communication infrastructure.

Financial Sector: ASN holders from the banking, financial services, and insurance industries fall under this category. Organizations in this sector depend heavily on secure and reliable Internet routing, particularly for online banking and financial transactions.

Enterprise-Datacenter Sector: This sector covers ASN holders from several industries and organizations, including healthcare, education, government, and more. It represents a diverse group with varying levels of routing security compliance.

A clear framework was established for categorization of readiness:

  • No Compliance: Entities with a score of 0.
  • Lagging — Low Compliance: Scores above 0 but ≤ 0.500.
  • Aspiring — Moderate Compliance: Scores > 0.500 but < 1.000.
  • Ready — Full Compliance: A score of 1.000.
SectorRPKI ComplianceIRR Compliance
Enterprise-DatacenterReady – Full: 74
Lagging – Low: 7
Aspiring – Moderate: 6
No Compliance: 24
Ready – Full: 103
Lagging – Low: 2
Aspiring – Moderate: 5
No Compliance: 1
FinancialReady – Full: 10
Lagging – Low: 1
No Compliance: 17
Ready – Full: 27
Lagging – Low: 1
No Compliance: 0
Telecom-ISPReady – Full: 88
Lagging – Low: 10
Aspiring – Moderate: 17
No Compliance: 10
Ready – Full: 111
Lagging – Low: 2
Aspiring – Moderate: 10
No Compliance: 2
Table 1: RPKI and IRR compliance by sector.

The ratio of ‘No Compliance’ for both RPKI and IRR, sector-wise, is as follows:

SectorRPKI ComplianceIRR Compliance
Enterprise-Datacenter21.62%0.90%
Financial60.71%0.00%
Telecom-ISP8%1.6%
Table 2: RPKI and IRR compliance by percentage.

Insights from Sector-wise Grouping

While commendable adherence to routing security practices exists, variations in RPKI compliance present avenues for enhancement.

Enterprise-Datacenter Sector: This sector demonstrates strong compliance in both Routing Information practices. In RPKI compliance, there are 74 entities with full compliance, 7 with low compliance, 6 with moderate compliance, and 24 with no compliance. In IRR compliance, 103 entities exhibit full compliance, 2 have low compliance, 5 have moderate compliance, and only 1 has no compliance. This sector has a notably better performance in terms of IRR compliance.

Financial Sector: The Financial sector shows a mixed performance in Routing Information practices. In RPKI compliance, there are 10 entities with full compliance, 1 with low compliance, and 17 with no compliance. In IRR compliance, 27 entities are fully compliant, and 1 has low compliance. This sector has a high level of compliance in IRR but a notable gap in RPKI compliance.

Telecom-ISP Sector: This sector leads in RPKI compliance with 88 entities having full compliance, 10 with low compliance, 17 with moderate compliance, and 10 with no compliance. In IRR compliance, 111 entities exhibit full compliance, 2 have low compliance, 10 have moderate compliance, and 2 have no compliance. While this sector demonstrates strong compliance, there is room for improvement in RPKI compliance.

Key Risks Associated with Non-Compliance of IRR and RPKI – Internet Routing Domain

Non-compliance with implementing IRR and RPKI poses specific risks to each sector. A common risk associated with noncompliance for all three sectors is that it undermines the overall trust in digital infrastructure critical for modern business and communication.

Here’s a non-exhaustive list of key risks associated with non-compliance in each sector:

Enterprise-Datacenter Sector:

  1. Non-compliance increases susceptibility to attacks like route hijacking or traffic interception, jeopardizing client data and services.
  2. Incidents resulting from poor routing security can lead to significant reputational damage, affecting client trust and business viability.
  3. Routing incidents can disrupt operations, leading to downtime, loss of service, and financial losses.

Financial Sector:

  1. The financial sector is a prime target for cybercriminals. Non-compliance can lead to financial fraud or data breaches, impacting both the institutions and their customers.
  2. Security incidents can erode consumer confidence, essential for financial institutions, potentially leading to loss of business.

Telecom-ISP Sector:

  1. ISPs face network instability or downtime risks due to routing security incidents, impacting many users and businesses.
  2. Non-compliance can lead to compromised network integrity, making the network unreliable for users and businesses that depend on it.
  3. ISPs can inadvertently become vectors for the spread of cyberattacks, affecting broader network segments.

Policy Recommendations

The insights derived from this data-driven analysis serve as the foundation for informed policy recommendations tailored to address sector-specific challenges and harness opportunities for improvement.

  1. EnterpriseDatacenter Sector: Maintain high IRR compliance and work towards reducing RPKI compliance variability. Encourage best practices sharing among entities. NCERT provides capacity-building training in these areas for data centers and enterprise networks through sectorial CERTS.
  2. Financial Sector: Leverage strong IRR compliance as a foundation for improving RPKI practices. Invest in RPKI training and awareness programs. The compliance framework of the State Bank requires an update, for which input should be sought from the Electronic Certificate Accreditation Council (ECAC) regarding the national infrastructure readiness for Public Key Infrastructure (PKI).
  3. Telecom-ISP Sector: Focus on elevating moderate compliance entities to full compliance in both IRR and RPKI. Establish a system of credits or ratings that highlights and incentivizes adherence to best practices in routing security. This approach acknowledges the efforts of compliant entities and motivates others in the industry to elevate their security standards, ultimately leading to a more robust and secure Internet infrastructure.

Conclusion

These insights empower us to forge policies that enhance the security and accessibility of the Internet, safeguarding its future as a reliable global resource.

As the MANRS community, including the Mentors and Ambassadors, navigate the waters of routing security, our collective effort to uphold and advance these essential security measures will shape the digital landscape for generations to come. Data-driven insights are our compass, guiding us toward a more secure and connected future.

Mujtaba Hussain has 12 years of experience in ICT and cybersecurity. He was a 2023 MANRS Ambassador, working with guidance from Harish Chowdhary and Ryan Polk.

Leave a Comment