Conference Agenda
Overview and details of the sessions of this conference. Please select a date or location to show only sessions at that day or location. Please select a single session for detailed view (with abstracts and downloads if available).
|
Daily Overview |
| Session | ||
Security Policy-2: From Rip-and-Replace to Route-and-Verify: Policy Implications of Real-Time Infrastructure Threat Detection for Securing Communications
| ||
| Presentations | ||
From Rip-and-Replace to Route-and-Verify: Policy Implications of Real-Time Infrastructure Threat Detection for Securing Communications 1: uc san diego, United States of America; 2: johns hopkins university The Salt Typhoon campaign — in which Chinese state-sponsored actors compromised lawful intercept systems across major U.S. carriers, enabling real-time geolocation and interception of millions of Americans — demonstrated that the security of communications infrastructure cannot be assured through supply chain exclusion or network hardening alone. Adversaries who control or compromise network infrastructure can surveil, disrupt, or extract intelligence from communications regardless of encryption, and current policy tools are structurally unable to address this threat for users operating through non-cooperative network infrastructure. This paper examines the policy implications of an emerging technical paradigm — real-time infrastructure verification and adversary-aware routing [1, 2] — developed under the AVOID/REVEAL research program (funded by the U.S. NSF and the Department of Defense [3]). This paradigm combines passive radio access network (RAN) fingerprinting to classify base station vendors, mobile core anomaly detection, and topology-aware Internet overlay routing that leverages router geolocation and vendor fingerprinting to steer communications away from adversary-controlled infrastructure. Unlike the prevailing policy approach of banning untrusted vendors from domestic networks, this paradigm enables users to detect and route around threats at runtime, wherever they connect — including in foreign networks where U.S. procurement rules have no reach. We analyze how this capability intersects with the responsibilities of multiple federal agencies. First, we argue that the FCC’s Covered List and rip-and-replace framework, while necessary, addresses only a fraction of the threat surface — domestic small carriers — and needs a complementary runtime verification policy dimension. Second, Salt Typhoon demonstrated that sophisticated adversaries can exploit trust assumptions embedded throughout communications infrastructure — not just in equipment from banned vendors, but in core network systems operated by major U.S. carriers. Current policy responses focus on operator-side hardening (patching, configuration auditing, mandatory reporting), but no existing framework addresses the user’s ability to independently assess the infrastructure their communications traverse — the specific capability that AVOID/REVEAL proposes. Third, we propose that NTIA’s National Strategy to Secure 5G and its emerging 6G security principles should extend beyond supply chain trust to encompass Internet path transparency. Remotely fingerprinting and geolocating network infrastructure many hops away remains a formidable technical challenge — current methods achieve useful but imperfect coverage, and adversaries can attempt to subvert fingerprinting by spoofing device signatures (e.g., making equipment from a banned vendor mimic responses of a trusted one). Realizing the full potential of infrastructure-aware routing will require sustained R&D investment alongside policy frameworks that support it: international auditing regimes among allied nations that can ground-truth remote inferences, regulatory mechanisms to deter or detect fingerprint spoofing, and development of transparency standards analogous to software bills of materials (SBOMs) but for network routing provenance. Fourth, we connect this work to NTIA’s Public Wireless Supply Chain Innovation Fund, which has invested over $140 million in open, interoperable RAN alternatives to Huawei and ZTE and is now pivoting toward AI-native RAN architectures. The Innovation Fund’s statutory mandate includes promoting security features for multi-vendor networks and defining objective compliance criteria for interoperable equipment — yet no current funding track addresses independent verification that deployed infrastructure actually matches its claimed provenance. We argue that as the U.S. promotes an exportable Open RAN stack as a global alternative to Chinese vendors, the ability to independently fingerprint and verify base station equipment in the field — exactly what AVOID demonstrates — becomes a critical complement to supply chain diversification, both for domestic assurance and as a trust-building capability for allied nations adopting U.S.-backed alternatives. Finally, we consider export control tensions: defensive infrastructure intelligence tools that identify adversary-controlled base stations and routing paths have inherent dual-use characteristics that will require Commerce/BIS classification guidance as these capabilities mature toward commercial availability for allied nations. Our analysis draws on technical proof-of-concept results from the AVOID Puck (RAN vendor classification achieving high-confidence real-time vendor predictions) and AVOID-Path (topology-aware overlay routing using CAIDA’s Internet measurement infrastructure), combined with a systematic review of post-Salt Typhoon legislative proposals, FCC rulemakings, NIST guidance documents, and NTIA strategy frameworks through early 2026. We find that current policy is overwhelmingly reactive — focused on removing known-bad equipment and hardening existing systems — while the threat model demands proactive, continuous infrastructure awareness. We conclude with specific recommendations for each agency to bridge this gap, and discuss how the research community can contribute measurement science foundations for an auditable, transparent communications infrastructure. | ||
