NIST works with industry partners to advance the research, standardization and adoption of technologies necessary to increase the security, privacy, resilience and performance of networked systems. This includes resolving systemic vulnerabilities in existing and emerging critical network infrastructures and advancing the development of potentially disruptive technologies to improve the trustworthiness of future networks.
NIST seeks to innovate and apply the measurement science necessary to establish a technical basis for trustworthy networks.
The scope and focus of NIST's work in Trustworthy Networks guided by specific identified national priorities and goals, including
The National Cybersecurity Strategy and Implementation Plan
The Federal Cybersecurity Research and Development Strategic Plan priorities to:
The National Standards Strategy for Critical and Emerging Technologies priorities to:
NIST's goals in this program are to improve the security, resilience and performance of the communication infrastructures that underlie our network-centric society. Our work cultivates trust in current and emerging network technologies by developing and applying innovative measurement techniques, improving the quality and timeliness of consensus standards, and providing tools and guidance necessary to expedite adoption of emerging network technologies.
Current project areas and select recent contributions in this program include:
Please see individuals project descriptions for complete lists of contributions including research publications, standards specifications, software tools, guidance documents, workshops, etc.
The section below lists selected recent technical contributions in Trustworthy Networks Research.
Product | Reference |
---|---|
Presentation, Invited | Montgomery D., The Role of Standardization, NSF Workshop: Towards Re-architecting Todays Internet for Survivability, Northwestern University, November 2023.
|
Conference Publication | Hoeger N., Rodday N., Borchert O., Dreo Rodosek G., Path Plausibility Algorithms in GoBGP, 19th International Conference on Network and Service Management (CNSM), Niagra Falls, Canada, October 2023.
|
Presentation | Sriram K., Azimov A., Bogomazov E., Bush R., Patel K., Snijders J., ASPA-based BGP AS_PATH Verification and Route Leaks Solution, NANOG 89, San Diego, CA, October 2023.
|
Standards Specification | Sriram K., Lubashev I., Montgomery D., Source Address Validation Using BGP UPDATEs, ASPA, and ROA (BAR-SAV), IETF Internet Draft (Standards Track, SIDROPS Working Group), September 2023.
|
Standards Specification | Azimov A., Bogomazov E., Bush R., Patel K., Snijders J., Sriram K., BGP AS_PATH Verification Based on Autonomous System Provider Authorization (ASPA) Objects, IETF Internet Draft, August 2023.
|
Standards Specification | Wu J., Li D., Liu L., Huang M., Sriram K., Source Address Validation in Inter-domain Networks Gap Analysis, Problem Statement, and Requirements, IETF Internet Draft, August 2023.
|
Presentation, Invited | Sriram K., ASPA-based BGP AS_PATH Verification and BAR-SAV for Mitigation of IP Address Spoofing, Internet2 Webinar, August 2023.
|
Presentation, Invited | Montgomery D., NIST Efforts to Accelerate Standardization and Support Adoption of BGP Security Technologies, Federal Communications Commission Border Gateway Protocol Security Workshop, July 2023.
|
Presentation, Invited | Montgomery D., BGP Security Level Set Problem Space and Emerging Solutions, Federal Communications Commission Border Gateway Protocol Security Workshop, July 2023.
|
Presentation | Bruijnzeels T., Borchert O., Ma D., de Kock T., Human Readable ASPA Notation, IETF 117 Conference, SIDROPS Working Group, San Francisco, July 2023.
|
Presentation | Bruijnzeels T., Borchert O., Ma D., de Kock T., Human Readable Validate ROA Payload Notation, IETF 117 - SIDROPS Working Group, San Francisco, July 2023.
|
Standards Specification | Sriram K., Montgomery D., AS Hijack Detection and Mitigation, IETF Internet Draft (Standards Track, SIDROPS Working Group), July 2023. |
Standards Contribution | Sriram K., Azimov A., Bogomazov E., Bush R., Patel K., Snijders J., Update on BGP AS_PATH Verification Based on ASPA Objects, SIDROPS WG Meeting, IETF 117, San Francisco, CA, July 2023.
|
Panel Session, Invited | Montgomery D., et. al., Working with Governments to Progress Routing Security, Internet Society Routing Security Summit 2023, July 2023.
|
Standards Specification | Bruijnzeels T., de Kock T., Borchert O., Ma D., Human Readable Validate ROA Payload Notation, IETF SIDROPS Working Group, July 2023.
|
Presentation, Invited | Sriram K., An Overview of ASPA-based BGP AS_PATH Verification, Routing Security Workshop hosted by Amazon, Seattle, WA, June 2023. |
Workshop, Invited | Sriram K., Montgomery D., Amazon Internet Routing Security Roundtable, Invitation only workshop before NANOG 88., June 2023. |
Standards Specification | Borchert O., T.Bruijnzeels, D.Ma, de Kock T., Human Readable ASPA Notation, IETF SIDROPS Working Group, May 2023.
|
Standards Contribution | Sriram K., Azimov A., Bogomazov E., Bush R., Patel K., Snijders J., ASPA-based AS Path Verification Draft Update, SIDROPS WG Meeting, IETF 116, Yokohama, Japan, March 2023.
|
Presentation, Invited | Montgomery D., Cannon R., Practical BGP Security with RPKI - Problem Space, Emerging Solutions, USG Call to Action, Invited presentation to Office of the Director of National Intelligence (ODNI) Team Telecom work group, March 2023.
|
Presentation, Invited | Sriram K., ASPA, BAR-SAV, and IETF Standards, Invited seminar/guest lecture to a graduate student class, University of Connecticut, Storrs, CT, February 2023.
|
Workshop, Invited | Montgomery D., et al., Workshop: Securing the Public Key Infrastructure, Princeton Center for Information Technology Policy, December 2022. |
Standards Contribution | Sriram K., Lubashev I., Montgomery D., Lowering Improper Block and Improper Admit for SAV The BAR-SAV Approach, SAVNET WG, Proceedings of the IETF 115, London, UK, November 2022., November 2022.
|
Standards Contribution | Sriram K., Lubashev I., Montgomery D., An Update on Source Address Validation Using BGP Updates, ASPA, and ROA (BAR-SAV), SIDROPS WG, Proceedings of the IETF 115, London, UK, November 2022., November 2022.
|
Standards Contribution | Sriram et al. K., Update on the ASPA-based AS Path Verification Draft, SIDROPS WG, Proceedings of the IETF 115, London, UK, November 2022., November 2022.
|
Standards Contribution | Kumari W., Sriram K., Hannachi L., Haas J., Deprecation of AS_SET in BGP, IDR WG, Proceedings of the IETF 115, London, UK, November 2022., November 2022.
|
Report | Montgomery D., et. al. members of BITAG Technical Working Group on Routing Security, The Security of the Internets Routing Infrastructure: A Broadband Internet Technical Advisory Group Technical Working Group Report, Security of the InteBroadband Internet Technical Advisory Group Technical Working Group Report., November 2022.
|
Standards Specification | Gilad Y., Goldberg S., Sriram K., Snijders J., Maddison B., The Use of Maxlength in the RPKI, IETF Request for Comments, RFC-9319 / BCP 185, October 2022.
|
Standards Specification | Sriram K., Design Discussion of Route Leaks Solution Methods, IETF Internet Draft (Informational), September 2022. |
Standards Specification | Heitz J., Sriram K., Dickson B., Heasley J., BGP Well Known Large Community, IETF Internet Draft, September 2022.
|
Standards Specification | Kumari W., Sriram K., Hannachi L., Haas J., Deprecation of AS_SET and AS_CONFED_SET in BGP, IETF Internet Draft (IDR Working Group), September 2022.
|
Standards Contribution | Sriram K., Lubashev I., Montgomery D., Source Address Validation Using BGP UPDATEs, ASPA, and ROA (BAR-SAV), IETF SIDROPS WG Meeting, Proceedings of the IETF 114, July 2022.
|
Standards Contribution | Sriram K., Lubashev I., Montgomery D., Source Address Validation Using BGP UPDATEs, ASPA, and ROA (BAR-SAV), IETF SAVNET WG Meeting, Proceedings of the IETF 114, July 2022.
|
Proposal | Montgomery D., Rose S., Sriram K., Borchert O., Santay D., Trustworthy Networks Research, CTL FY2023 Project Plan, July 2022. |
Standards Specification | Azimov A., Bogomazov E., Bush R., Patel K., Sriram K., Route Leak Prevention and Detection using Roles in UPDATE and OPEN Messages, IETF Request for Comments (RFC-9234), May 2022.
|
Standards Specification | Sriram K., Azimov A., Methods for Detection and Mitigation of BGP Route Leaks, IETF Internet-Draft (Standards Track, IDR Working Group), April 2022.
|
Standards Contribution | Sriram K., ASPA Verification Procedures: Enhancements and RS Considerations, IETF 113 SIDROPS WG Meeting, March 2022.
|
Software | Borchert O., Hannachi L., Lee K., Sriram K., Montgomery D., BGP Secure Routing Extension (BGP-SRx) Suite 6.2 - BGP-SRx - Test Framework Generator for ASPA, NIST Open Source Reference Implementation, March 2022. |
Presentation | Borchert O., Lee K., Sriram K., Montgomery D., Gleichmann P., Adalier M., BGP Secure Routing Extension: Reference Implementation and Test Tools for Emerging BGP Security Standards, Security Research Review seminar, January 2022. |
Collaborators = ARIN, AT&T, Akamai, Akamai Technologies, Arrcus, Boston University, CableLabs, Charter Communications, Cisco, Cloudflare, Comcast, Fastley, Fastly, Federal Communications Commission, George Washington University, Georgia Tech University, GoDaddy, Google, Hebrew University of Jerusalem, Huawei, IIJ, ISOC, Internet Initiative Japan, Internet Neutral Exchange Association (INEX), Internet Society, Internet2, Juniper Networks, Kentik, Lumen, NCTA, NIST, NLnet Labs, NTIA, NTT, Netscout, Princeton University, Qrator Labs, RIPE NCC, Research institute CODE, SkyUK, Tsinghua University, Universitaet der Bundeswehr Muenchen, University of Chicago, University of Connecticut, University of Kentucky, University of Twente, Yandex, ZDNS, Zhongguancun Laboratory
Product | Reference |
---|---|
NIST Publication | Borchert O., Kerman A., Rose S., Souppaya M., et. al., Implementing a Zero Trust Architecture - NIST Special Publication 1800-35D, NCCoE - Preliminary Draft, August 2023.
|
NIST Publication | Borchert O., Howell G., Kerman A., Rose S., Souppaya M., et. al., Implementing a Zero Trust Architecture - NIST Special Publication 1800-35B, Preliminary Draft, July 2023.
|
Panel Session | Rose S., Resnick R., Connelly S., Dept. of State Cybersecurity Fireside Chat, Department of State Cybersecurity Training Series, July 2023.
|
Presentation | Rose S., Kerman A., Symington S., NIST NCCoE: ZT Architecture and Demonstration Briefing, Federal Interagency Zero Trust Exchange, March 2023. |
Presentation, Invited | Rose S., Borchert O., Zero Trust Archtecture, ATIS TOPS Enhanced Zero Trust and 5G Meeting Series, February 2023. |
Presentation | Rose S., Blue Cyber Event Tuesdays - Ask Me Anything Zero Trust for Small Businesses, DoD SBBIR Blue Cyber Event Series, January 2023. |
Presentation | Rose S., Zero Trust and FinTech, IP Services Technical Webinar Series, November 2022. |
Panel Session | Rose S., Hills C., Brodbent J., Cruz Cain M., Meeting Mandates with Identity Driven Zero Trust, Carasoft/BeyondTrust webinar panel, September 2022. |
Presentation | Kerman A., Rose S., Inside the Making of a Zero Trust Architecture, RSA Conference 2022, June 2022. |
Panel Session, Invited | Borchert O., Overcoming Identity Challenges to Meet the Federal Governments Zero Trust Memo, ATARC - Round Table Discussion, May 2022. |
NIST Publication | Rose S., Planning for a Zero Trust Architecture: A Guide for Federal Administrators, Cybersecurity White Paper, National Institute of Standards and Technology (Gaithersburg MD)., May 2022. |
Presentation | Rose S., Demystifying Zero Trust, Air Force SBIR/STTR CISO Weekly Ask Me Anything Seminar Series, January 2022. |
Collaborators = Amazon Web Services, Appgate, Broadcom Software, Cisco Systems, DHS CISA, DigiCert, F5, Forescout, Google Cloud, IBM, Ivanti, Lookout, MITRE, Mandiant, Microsoft, Okta, PC Matic, Palo Alto Networks, Ping Identity, Radiant Logic, SailPoint, Tenable, Trellix, US Department of Defense, VMware, Zimperium, Zscaler
Product | Reference |
---|---|
Proposal | Rose S., et_al., Zero Trust Architecture (ZTA) for O-RAN, WG11-2023-08 Work Item Description, January 2024.
|
Standards Contribution | Borchert O., Rose S., NIST-2023.09.26-WG11-CR0003-SecReqSpec-Drafting-Rule-Adjustment, O-RAN Change Request, September 2023. |
Standards Contribution | Borchert O., Rose S., NIST-2023.09.26-WG11-CR0002-SecRecSpec-O1-Interface-Modification, O-RAN Change Request, September 2023. |
Standards Contribution | Rose S., NIST-2023.09.22-WG11-CR-0001-AIRMF, O-RAN Change Request, September 2023. |
Report | Montgomery D., et. al. other members of CSRIC 8 Working Group 3, Recommendations on the Role of the FCC in Promoting the Availability of Standards for More Secure, Reliable 5G Environment Through the Use of Virtualization Technology, Communications Security, Reliability, and Interoperability Council VIII, June 2023. |
Report | Montgomery D., et. al. members of CSRIC 8 Working Group 3, Report on How Virtualization Technology Can Be Used to Promote 5G Security and Reliability, Communications Security, Reliability, and Interoperability Council VIII, December 2022.
|
Collaborators = ANDRO Computational Solutions, AT&T, Altiostar Networks, CTIA, Cisco, Comtech Telecommunications Corp., Cox Communications, Cybersecurity and Infrastructure Security Agency (CISA ECD), Dell, Dell Technologies, Deutsche Telekom, Ericsson, FCC, FirstNet, Hewlett Packard Enterprise, Intel Corporation, LLC, MITRE, Mavenir, Microsoft Corporation, Motorola Solutions, NTIA, National Security Agency (NSA), Nokia, Palo Alto Networks, Qualcomm Incorporated, Rakuten, Rural Wireless Association, T-Mobile USA, Verizon
Product | Reference |
---|---|
Standards Specification | Lear E., Rose S., A YANG Data Model for Reporting Software Bills of Materials (SBOMs) and Vulnerability Information, IETF RFC 9472, October 2023.
|
Software | Singh M., Montgomery D., Formal Models Of IoT Onboarding Protocols, Software Repository, January 2022. |
Collaborators = Cisco Systems
Product | Reference |
---|---|
Journal Publication | Wang Z., Use of Supervised Machine Learning to Detect Abuse of COVID-19 Related Domain Names, Computers and Electrical Engineering, Volume 100, May 2022. |
Journal Publication | Wang Z., Guo Y., Montgomery D., Machine Learning-Based Algorithmically Generated Domain Detection, Computers and Electrical Engineering, Volume 100, May 2022. |
Product | Reference |
---|---|
Presentation, Invited | Montgomery D., USGv6 Program: Facilitating the Transition to IPv6-Only Networks, The IEEE International Conference on Artificial Intelligence, Blockchain, and Internet of Things, September 2023.
|
Presentation, Invited | Montgomery D., USG IPv6 Initiative: Completing the Transition to IPv6-only Networks, CyberOZ 2023: Engineering the Future of Cybersecurity, IPv6 and AI Workshop, September 2023. |
Presentation, Invited | Montgomery D., USGv6 Program Facilitating the Transition to IPv6-Only Networks, IPv6 Federal Forum, June 2023. |
Presentation, Invited | Montgomery D., USG IPv6 Initiative: Completing the Transition to IPv6-Only Networks, Presented to the G7 Digital Technical Standards Working Group Meeting, June 2022. |
Presentation, Invited | Montgomery D., USG IPv6 Initiative: Completing the Transition to IPv6-Only Networks, Presented to the 2022 N-Wave Stakeholders and Science Engagement Summit, March 2022. |