Skip to main content

A Systematic Literature and Expert-Based Analysis of Parameters Influencing Lightweight Secure Borde

Page 1


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056 Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

A Systematic Literature and Expert-Based Analysis of Parameters Influencing Lightweight Secure Border Gateway Protocols for Internet Service Providers.

Barongo Mong’are 1, Stephen T. Njenga 2, Daniel Makupi 3, Peter Maina Mwangi 4

ABSTRACT: Internet Service Providers (ISPs) form the backbone of global Internet connectivity, relying on routing protocols such as BGP to exchange reachability information across autonomous systems. Securing these protocols is critical, as vulnerabilities can lead to route hijacking, leaks, and large-scale service disruptions. Analyzing routing protocols for ISPs, therefore, requires examining key performance and security parameters that influence their efficiency and resilience. Metrics such as convergence time, CPU utilization, protocol overhead, and security effectiveness provide the foundation for designing lightweight yet secure BGP solutions. This paper discusses the concept of secure, lightweight routing protocols for Internet Service Providers (ISPs) through a systematic literature review. Following the Kitchenham system, we evaluated peer-reviewed articles published in 2020 - 2025 using IEEE Xplore, ACM Digital Library, ScienceDirect, and SpringerLink. The overview instruments to divide them into cryptographic, based-trust, anomaly-detection, and hybrid protocols, and outline their strengths and weaknesses, and areas of application. It is observed that lightweight protocols such as L-SBGP achieve lower computational overload, faster convergence, and greater scalability, but are not easy to deploy in large ISP networks. Such significant design parameters are convergence time, CPU consumption, security efficiency, and protocol overhead. In the future, such parameters should be leveraged to develop optimized Lightweight Secure BGP solutions

INDEX TERMS: Lightweight Secure BGP, Internet Service Providers (ISPs), Routing Protocol Security, Convergence Time Optimization, Anomaly Detection in BGP, Energy-Aware Routing.

I. Introduction

ISPs are significant in interconnecting networks worldwide and forwarding data over inter-domain protocols across Autonomous Systems (ASes) [1]. The most widely used protocol in this regard is the Border Gateway Protocol (BGP), butitwas not initiallyenvisionedto have robustsecuritycapabilities.This lackhasexposeditto securitythreats,includingprefixhijacking,routeleaks,andman-in-the-middleattacks.Secureversions,suchasSBGP, BGPsec, and RPKI, have been proposed over the years but are less likely to succeed. Due to theirhigh computationaloverhead,complexkeymanagement,andsmall-scale.

To address such problems, designers have studied lightweight, secure routing protocols that aim to provide high levels of security assurance while minimizing computational, communication, and energy overhead. ISPs seeking scalable, cost-effective, and energy-efficient solutions are particularly concerned with these protocols [2]. Nonetheless, none of this has been comprehensively synthesized, especially in the ISP setting .This systematic literature review (SLR) seeks to address the gap by analyzing secure, lightweight routing protocols applicable to ISPs, identifyingtheir pros andcons, andcharacterizingtheiruse inapplications. The reviewofferscluesonhow future Lightweight Secure BGP (L-SBGP) protocols can be designed to meet the performance and security requirementsofcontemporaryISPs,identifyingkeydesignparametersandoptimizationmethods.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

II. Background of the Study

Inter-domain routing security has a long history, and is associated with the development of the Border Gateway Protocol (BGP), first introduced in 1989 as a replacement of the former Exterior Gateway Protocol (EGP). BGP became the basis for global Internet routing and enabled Autonomous Systems (ASes) to exchange reachability information. BGP,however, was developed at a time whenthe Internet communitywas small andtrusting. Thus, securitycontrols,includingrouteandpathvalidation,werenotincorporatedintotheoriginaldesign.

With the proliferation of the Internet in the 1990s and 2000s, vulnerabilities such as prefix hijacking, route leakage,andpathmanipulationhavebecomemorevisible.Thehigh-profileincidentsshowedtheextenttowhicha single malicious or poorly configured announcement can bring down global connectivity. Researchers responded bysuggestingcryptographicvalidationmechanismsandtrustmodels,suchasSecureBGP(S-BGP),soBGP,BGPsec, andRPKI-basedmechanisms.Thesesolutionsenhancedsecurity,buttheyhavehighcomputationaloverheadand complexity of deployment. This historical development has prompted increased attention to lightweight, secure versionsofBGPoptimizedforamodernISPsetting.

III. Related Work

The continuing but long‐standing BGP flaws such as prefixhijacking, route leaks, and path manipulation have promptedresearcherstomakesecuringBGPwithinInternetServiceProviders(ISPs)amajorareaofinvestigation. EventhoughstandardBGPcannotbedonewithoutininter-domainroutingandaccessingtheInterneteverywhere, it does not provide any intrinsic protection of message authentication or integrity validation. Thus, the ISP infrastructure is still vulnerable to outages due to deliberate attacks and unsuccessful misconfigurations. One incorrect routing update may spread very fast leading to outages, traffic redirection and creation of security breachesacrosstheinterrelatednetworks.Realizingtheexistenceoftheseweaknesses,scholarshaveattemptedto strengthen BGP by developing Secure BGP (S-BGP) variants [3]. Such improvements can be broadly divided into three categories: cryptographic validation, which is used to verify the authenticity of the route origins and route paths; trust-based frameworks, which aim to establish trust between autonomous systems; and incremental deploymentstrategies,whicharemeanttobedeployedincrementallyandinawaythatiscompatiblewithandwill notbreaklegacyBGP.AllthesestrategiescombinedarethegroundworkuponwhichISProutingisguaranteedto besecureandoperational[4].

Zhang et al. (2023)

ToaddressoneofthemostsignificantdrawbacksoftraditionalSecureBGPtools,i.e.theenormouscomputational cost of cryptographic verification, Zhang et al. (2023) offered a refined BGPsec deployment framework. In their model, they proposed an aggregated scheme of signature validation allowing multiple routing update to be validatedincooperationinsteadofone.ThisoptimizationenhancedlargeInternetServiceprovider(ISP)network convergence speed by reducing the number of cryptographic operations needed to carryout. It was found in the experimentsthatsignaturevalidationaggregationsignificantlyloweredtherouterCPU-usage,allowingdevicesto handlealargernumberofrouteupdateswithoutdelay[5].

The paper further pointed out the practical significance of convergence rate, warned that a long convergence periodwillcausetrafficengineeringtobeunstable,andwouldcompromiseservice-levelguarantees.Eventhough the solution made it more efficient, the authors were aware that cryptographic complexity still presented a bottleneck in high-speed ISP backbones, where thousands of updates are handled in a second. Moreover, its implementation continued to be troublesome, due to difficulties in integration with the current BGP implementationsandrepeatedmanagementofcryptographic keys. However, thestudyconducted byZhanget al.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056 Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

wasstillimportantinillustratingthattheSecureBGPcanbe optimizedinnetworksofISPscalesandthusaclear waytogoonthesecurity-orientedroutingprotocolswhicharefeasibleandimplementableispresented[6].

Amin & Patel (2022)

AminandPatel(2022)presentedacomparativeinvestigationoftwomethods,i.e.,soBGP(SecureOriginBGP)and psBGP(PrettySecureBGP),thatareaimedatimprovingroutingsecuritytoInternetServiceProviders(ISPs).This was necessitated by the incompetence of the old BGP, particularly the lack of authentication of routing announcements, and checking of AS paths, which does not assure protection against hijacking and misconfiguration,whichexposestheISPstohijackingandmisconfiguration.Thestudymeasuredtheeffectiveness ofsoBGPinenhancingsecuritythroughthedeploymentofadistributedpublic-keyinfrastructuretoauthenticate route origins thus limiting the extent to which special prefixes can be propagated to authenticated autonomous systems[7].

The authors thus highlighted that there are a number of benefits that are common to these approaches. Policy validationcanbedonewithasmallamountofcryptographicoverheadwithSoBGP,andthetrust-basedmodelof psBGPisflexiblepercomputationalcost.However,thetwostrategiesdemonstratedasmallamountofscalability: soBGP was unable to withstand path-manipulation attacks, and psBGP required a large number of trust relationships, which limited its scalability in large ISP networks. Amin and Patel concluded that despite the fact that both techniques improved security compared with traditional BGP, they have not offered full security and moresecureBGPsolutionsareneeded.

Lee & Nakamura (2022)

Lee and Nakamura (2022) designed a systematic experiment on the effectiveness of Secure BGP techniques and specifically on the validation of prefixes and paths in the simulated environment of ISP. The research aimed at evaluatinghowsuchmechanismslikeS-BGPandBGPsecwouldperformintopologiesthatcouldbeconsideredas representativeoflarge-scaleinter-domainnetworks.Theexperimentdemonstratedthatcryptographicvalidation significantlyenhancedroutingintegritybyensuringtheverificationoftheoriginofprefixandthesequentialorder of a list of Autonomous Systems (AS) that are passed through it. In this way, the success rate of hijacking was significantlylowered,aswellasthelikelihoodofspreadingmaliciousroutesdecreasedsignificantly[8].

Perhaps the most significant strengths of the study were that BGPsec was empirically tested in nearly realistic settings,andtheresultsprovideduswithanimportantunderstandingofitsapplicabilityinpracticalsettingsthat go far beyond thehypothesis of anytheoreticalmodel. Liet al.howeveralso revealed severe shortcomings. Even though the positioning of the digital signatures per hop enhanced security it was a heavy burden to the routers. This caused convergence times to be slow andthe transmissionof routingupdates was also delayed, a condition that may be quite problematic in high-speed ISP backbones, where latency is critical. Overall, the authors concluded that, despite the factthat cryptographic protectionisinevitableto ensure the securityofinter-domain routing,optimizationmechanismsarenecessarytofacilitatesoundsecurityguaranteesandtheperformanceofISP networks[9].

Khan et al. (2020)

Khan et al. (2020) considered the progressive deployment of S-BGP and BGPsec on top of multi-Autonomous System (AS) topology as a challenge of securing large Internet Service Provider (ISP) networks. The researchers emphasized a severe issue: despite the fact that secure BGP protocols such as S-BGP and BGPsec give strong cryptographicguaranteesto routesourcecheckingandpath validation,theyhave beenchallengingtoimplement

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

inasinglewaveintheInternet,otherthanbeingoperationallyintensive.Phasedimplementation,wherebyonlya partoftheISPsusethesecureBGPandtherestuselegacyBGP,wasproposedbyKhanandothers,thoughitmay stillbeofsomebenefitinregardtosecurity.

With simulations, they demonstrated that secure BGP implementation in only some ASes was effective in minimizingtheprobabilityofprefixhijacksandlimitingtheirspread.AlthoughonlysomeportionoftheASeshad implementedsecureBGP,badrouteannouncementswerelimitedtosmallerpartsofthenetwork.Thesefindings suggest that the step-by-step stage-by-stage implementation of deployment can be an effective way of stepping towards full implementation [10]. However, the researchers also pointed out significant difficulties: the implementation of secure and legacy systems did not go hand in hand, increasing the complexity of operations, creatingpolicytensions,andhavinganadministrativeburden.Byandlarge,accordingtoKhanetal.,incremental deploymentisacasetobeexcitedabout,yeteffectiveframeworksarestillneededtoallowbackwardcompatibility andsimplifyintegrationwithexistingISPinfrastructures[11]

IV. Methodology

Thestudycontinuesusingasystematicliteraturereview(SLR)andexpert-basedanalysis,basedontheprinciples of Barbara Kitchenham, the highly structured methodology of review used in software engineering. The methodology has been subdivided into three main steps, which include planning the review, the review, and reportingthe review. Theexpertanalysis also underpins thesystematic reviewto allowthat the parameters and findingsfoundcanberelatedtoactualInternetServiceProvider(ISP)routingandoperationalconstraints.

Figure 1: Security–Performance Trade-off in Existing Secure BGP Variants
Figure 2: systematicliteraturereviewbasedonBarbaraKitchenham’sguidelines.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Why Use Kitchenham's Methodology?

The systematic review process as created by Kitchenham is very well-known in software engineering due to its rigor,transparencyandrepeatability.Itensures:

i. Experimentaldeterminationandchoiceofliterature

ii. Organizedsystematicanalysisandcombinationofresults

iii. Minimizationofresearchereffect

iv. Fulldetailsofthereviewprocess

Kitchenham’s Key Guidelines:

1. Identifyresearchquestionsclearly

2. Establishanorganizedreviewprotocol

3. Applysearchtechniquesinseveraldatabases

4. Usetransparentinclusionandexclusioncriteria

5. Datashouldbeextractedinastandardway

6. Reflectonandsynthesizeresultsusingananalysis

7. Supportfindingsinaclearandtraceablemanner.

Expert-Based Analysis

In addition to the systematic literature review, this paper proposes a systematic expert examination in order to strengthen the process of identification and validation of the most significant parameters which influence Lightweight Secure Border Gateway Protocol (L-SBGP) design. Expert analysis is concerned with the operational context of working routing environments with ISP routing, and the issues of operational complexity, scalability, and resource constraints are especially important. The experts' contributions were from professionals with experienceinISPnetworking,routingprotocolimplementation,andnetworksecurity,andwerecomplementedby evidencereportedintheacademicliterature.

Objective1,whichaimedtoexamineparametersthatminimizecomputationalcostsinISProutingprotocols,was primarily used to validate the expert analysis. Professionals had assessed the comparative effects of parameters such as CPU utilization, convergence routing time, protocol overhead, energy consumption, and scalability. Their evaluationsfoundthatcryptographicvalidationoperations,especiallydigitalsignaturegenerationandverification, aretheprimarysourceofcomputationaloverheadinsecurevariantsofBGP.Theexpertresultswerequalitatively synthesizedtoputliteraturefindingsintoperspective,therebydemonstratingthattheproposedL-SBGparameters aretheoreticallyandpracticallyfeasibleforthedeploymentofISPintherealworld.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

3.1 Planning the Review

A. Research Questions:

Toachievetheresearchgoal,severalresearchquestionswereused.

i. RQ1:Whatarethecurrentsecure&lightweightprotocolsforISPs,theiradvantages,disadvantages, andapplicationareas?

ii. RQ2: What key design parameters & optimization techniques are employed to reduce computational,communication,andenergyoverhead?

iii. RQ3:WhatfuturedirectionsarerecommendedforlightweightsecureISProuting?

B. Search Strategy:

The systematic review's search strategy began with a well-designed approach to fully capture the relevant literature. The key instrument in this was the selection of the primary academic databases, namely IEEE Xplore, ACMDigitalLibrary,ScienceDirect,andSpringerLink.Itwasdecidedtousetheseplatformsbecausetheyprovidea broadrangeofpeer-reviewedarticlesoncomputernetworkingandcybersecurity,whichsimplifiestheprocessof locatinganinformativeworkonBorderGatewayProtocol(BGP)security.Inparticular,asetofkeywordshasbeen appliedtorestrictthesearchtotheidentificationofthemajorityofhelpfularticles. Thesearethefourkeywords, which are Secure BGP, BGP security, Prefix hijacking, and Routing protocol in ISPs. These groups of word associationswouldcontributetogatheringtheliteraturethatconveystheirdirectconcernwiththeexploitationof BGP vulnerabilities, the method of attack, and possible solutions to the same. In addition, to restrict the area of research investigation, itwas intentionally limited to the publications published within the range 2020-2025. All thestepsofsearchprocesssuchasdatabasesearchesandexclusioncriteriahavealsobeen describedindetailto achievereproducibilityandreporttransparency.

3.2 Conducting the Review

A. Inclusion Criteria:

Among the peer-reviewed publications, we limit ourselves to works on secure BGP mechanisms that are applied directly to inter-domain routing. The studies were selected to indicate experimental, simulation, or analyticalassessmentsofthesuggestedsolutions.Inparticular,thepublicationskeptincludedthosethatfocus on the practical context in ISP, outline remedial methods, and recommend security measures that can be deployed.

B. Exclusion Criteria:

C. We did not include non-peer-reviewed sources, such as editorials, commentaries, and white papers. Moreover,papersaddressingroutingalgorithmsbeyondBGPorthatdidnotaddressinter-domainrouting aspectswereexcludedfromthesynthesis.

D. Data Extraction and Synthesis:

A structured data extraction form was applied to every chosen study. The following information was culled: protocolname,yearpublished,threatmodeladdressed,mechanismtype(cryptographic,trust-based,anomaly detection,hybrid),simulationortestbedplatform,performancedata(convergencetime,packetdeliveryrate), highlights,limitations,anddeploymentconsiderations.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056 Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Thefollowingtableillustratesthedataextractionusedinthisstudy:

Table 1: Table illustrating data extraction used in this study Academic Database

of Journals Extracted

The analysis of the journal articles resulted in a split, as reflected in the large collections of scholarly publicationsshowninthetableabove.IEEEXplore(50)madethelargestcontributionamongthestudies,followed by ACM Digital Library (35), ScienceDirect (30), and SpringerLink (25). The reputations of these databases, in terms of publishing quality and recent peer-reviewed research on computer networking and Internet security, have made them even more popular. These sources ensured extensive coverage and representation in the literature. Having gathered data from these different repositories, the paper aims to provide comprehensive coverageof the various perspectives, experimentaldesigns, andsecurityframeworks developedinthe domainof BGProuting.

V. Reporting the Review

The increased rate at which Internet Service Provider (ISP) networks are growing in size and complexity has increased the requirement of sound routing systems. Though the available secure routing protocols are highly effective against cyber-attacks, they are prone to cause massive computational, communication, and energy overheads hence applicable only in small scales in real high-speed network environment. To escape such predicaments,lightweightsecureroutingprotocolshavebeensuggestedwhicharecapableofsustaininghighlevel of security and are efficient as well [12][13][14]. These protocols are needed in order to offer fast and reliable

Figure3: Flow chart for selecting the articles

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

dictumwithoutaddingcongestionandlatency.Thereviewexaminescurrentresearchonconstructionparameters, optimizationtechniques,andfutureavenuesforsecurelightweightISProutingprotocols.

RQ1: What are the current secure & lightweight protocols for ISPs, their advantages, disadvantages, and application areas?

To establish the current state and deployment readiness within the ISP environment, it is imperative to identify existing secure, lightweight routing protocols [15]. Such protocols are also important since ISPs need routing solutions that can achieve a high degree of security while simultaneously reducing overheads in computing, communication,andenergyconsumption.Suchprotocolsarereviewedusingseveralmainmarkers.Eachsolution isnamedbytheprotocolusedtoreferenceanddistinguishit,aswritteninthetechnicalliterature,e.g.,L-SBGP.The benefits explain the effectiveness and appropriateness of a protocol for particular environments, which are normally identified by comparison, e.g., lower CPU overhead. On the other hand, the drawbacks highlight the shortcomingsandareasforimprovementidentifiedinthereportedassessmentfindings,e.g.,thelackofsignificant testing. At last, the application areas identify the application domains where the protocol could be successfully implemented,accordingtodeploymentreports,e.g.,inregionalISPswithlimitedresources

Table 2: Comparison of Lightweight Secure Routing Protocols for ISPs

Protocol Type Advantages Disadvantages Applications

L-SBGP Hybrid Low overhead, fast convergence Limitedlarge-scalevalidation Medium-sizeISPs

SoBGP Cryptographic Origin&pathvalidation Highdeploymentcomplexity Nationalbackbones

pgBGP Trust-based Anomalydetectionviahistory Storage-intensive Monitoringsystems

GoBGP Extensible API-basedautomation Requires programming expertise Dynamic policy control

RQ2: What key design parameters & optimization techniques are employed to reduce computational, communication, and energy overhead?

These parameters and optimization schemes are quite important to understand to achieve the desired advancementinlightweightprotocoldevelopment.SinceISPsoperateatalargescaleandhandlelargevolumesof data,aslightincreaseinefficiencycanyieldsignificantoperationalsavings[16].Convergencetimeisanimportant parameterthatprovidesinformationonthespeedofconvergenceofroutingtablesfollowingchangesintopology; reducingdowntimeis a decisive concern,andthereforeconvergence timeisestimated tooccurina fewseconds, andthefastertheconvergencespeed,thebetterthenetwork'sfeasibility.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Formal Mathematical Definitions of Key Performance Parameters

Convergence Routing Time

Where:

 istheconvergencetime,

 representsthetimeatwhicharoutingchangeorfailureoccurs,and

 isthetimeatwhichtheroutingtablesreachastablestateagain.

CPU Utilization

Where:

 denotestheamountofprocessingpowerconsumedbyroutingoperations,and

 representsthetotalprocessingcapacityoftherouter.

Protocol Overhead

Where:

 referstothevolumeofcontrolorsignalingtrafficgeneratedbytheroutingprotocol,and

 representsthevolumeofactualuserdatatraffic.

Energy Consumption

Where:

© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1744

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

 isthetotalenergyconsumedduringroutingoperations,

 denotesthepowerconsumedduringaspecificroutingoperation,

 sisthedurationofthatoperation,and

 isthetotalnumberofroutingoperations.

From the above formulas, we can see that CPU utilization is another important metric that represents the processorloadwhengivenroutingupdates;itisusuallyexpressedasapercentageofthetotalavailableCPU,anda lower usage rate ensures scalability by lessening the burden on network equipment. Overhead in the protocol is alsohighandisdefinedastheextracontroltrafficcausedbytheprotocol;itismeasuredinpackets/bytes/sec,and itslowervaluesleavemorebandwidthtocarryrealdata.Lastly,energyefficiency,measuredinwattsorjoulesper update,reflectstheamountofpowerusedwhenmakingroutingdecisions;alowerenergyconsumptionlevelisnot onlycost-effectivebutalsoreducesthenetwork'soverallrunningcostsandenablessustainablemanagement.

RQ3: What future directions are recommended for lightweight secure ISP routing?

There is a need to lead possibly fruitful research paths such that future routing protocols will be resilient and effectiveandcapableofrespondingtothefutureissues.Withinthecontextofthethreatenvironmentshiftingand thecontinuouslygrowingISPnetworks,onecansingleoutdifferentstrategiesthatcanbehighlyrelevant[17].This maybethroughtheadditionofmachinelearningtoidentifyanomaliesdynamicallysothatnewpatternsofattacks canberespondedtoinrealtime.Anotherstyleofimplementationthatcanresultinahighlevelofsecurity,aswell asbesignificantlymoreresource-efficient,istheadoptionofmorelightweightcryptographicprimitives.Dynamic pathoptimizationisalsohelpfulinfacilitatingfacilityorloadbalancingandalso,istoleranttolinkfailures,making the service resilient. Lastly, energy-preserving routing algorithms should be developed to reduce power consumption, thereby saving on operating costs and, at the same time, making the operation of large-scale networksabitfriendlier

5.1 Design Rationale

The conventional secure version of BGP, including S-BGP and BGPsec, is overly dependent on per-hop cryptographiccomputations,whichincurhighcomputationalcosts,slowconvergence,andscalabilitychallengesin large Internet Service Provider (ISP) networks. These restrictions render full deployment problematic, especially in networks with limited resources or high speeds. This work aims to address these issues by proposing a LightweightSecure Border GatewayProtocol(L-SBGP)frameworkthatbalances routingsecurityand operational efficiency.

The L-SBGP framework proposed is an alternative to costly per-hop digital signatures, using lightweight hashbased validation and simple anomaly-sensitive filtering to prevent prefix hijacking and the propagation of malicious routes. The scheme is particularly intended to keep control-plane overheads and computational complexityataminimum,whilstofferingrapidconvergenceandareasonabledegreeofroutingsecurity,suitable fordeploymentinagloballyoperatingISP.

VI. Proposed Lightweight Secure BGP (L-SBGP) Framework

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

5.2 L-SBGP Control-Plane Architecture

TheL-SBGPframeworkisacontrolplaneframeworkmodeledandcomposedofthefollowinglogicalcomponents:

1. RouteUpdateListener:AcceptsroutingupdatesfromneighboringAutonomousSystems(ASes).

2. Lightweight Security Validator: This uses a hash-based system to verify the origin without incurring the highcostofcryptographicsignatures.

3. FilteringModule:Anomaly:Dropsroutingupdatesthatareanomalous,e.g.,simulatedprefixhijacking.

4. Policy and Optimization Engine: Imposes lightweight acceptance rules to prioritize valid routes and minimizeunnecessarypropagation.

5. RoutingDecisionEngine:Insertstestedroutesintothelocalroutingtableandsendsthemtoneighborsas needed.

All ASs are treated as independent routing entities, each with a local routing table and a set of peering relationships. The architecture prioritizes simplicity, scalability, and low resource usage, and is therefore appropriateforenvironmentsatthescaleofanISP.

5.3 Lightweight Route Validation Algorithm

L-SBGP uses lightweight route validation to ensure it spends little time on computational tasks without compromising security. The protocol does not rely on validating all AS hops with a complex cryptographic signature; instead, it uses a hash-based origin check, together with malicious route filtering, to determine route validity.

Algorithm 1: L-SBGP Lightweight Route Validation

1. RoutingupdateReceived[Prefix,AS-path,origin-AS].

2. Small-scalehashofPrefixandoriginal-AS.

3. Comparethecomputedhashsignaturewiththeroute'ssignature.

4. Confirmationmarksofasuspiciousroute.

5. Ifvalidationissuccessful,accepttheroute.

6. Discardroutingupdateotherwise.

The approach will significantly reduce processing overhead, though it would eliminate illegitimate or malicious routingannouncementsearlierintheprocess.

Figure 4: L-SBGP Control-Plane Architecture

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

VII. Google Colab–Based Performance Evaluation

6.1 Experimental Environment

APython-basedcontrol-planemodelwasusedtosimulatetheperformanceoftheproposedL-SBGPframeworkon GoogleColab.Thesimulationassumesinter-domainroutingandthedisseminationofroutingupdatesratherthan packet-by-packet forwarding. It allows for the experimental analysis of example routing performance metrics of interestinISPoperations.

The simulation environment focuses on the relative protocol behavior, enabling a fair comparison between legitimateroutingpropagationandmaliciousrouteinjectionscenariosunderthesamenetworkconditions.

6.2 Network Topology and Evaluation Scenarios

Atopologywithapopulationsizeof100AutonomousSystem(AS)nodeswassimulatedandanISPscale,30outof the100nodeswerechosentobeexamined.EachAScontainsaroutingtableaswellasarandomizedlistofinterdomainpeeringrelationships,asdeterminedbytherealisticinter-domainconnectivitypatterns.

Thescenariosofevaluationperformedincluded:

 Valid Prefix Announced by a Valid Origin AS: A valid prefix (10.0.0.0/24) is announced by a legitimate sourceAS.

 PrefixHijackingScenario:AnASattemptstopropagateafakerouteforanidenticalprefix.

The simulation measures the effectiveness of L-SBGP in advertising valid paths and repressing malicious routing announcements.

6.3 Performance Metrics

Theanalysisisbasedontheimportantcontrol-planeperformanceindicatorsthatareoftenutilizedtoanalyzeISP routing:

ConvergenceTime:Thetimeintervalittakesforroutingtablestostabilizeafteraroutingupdate.

ControlMessageOverhead:Thesumofroutingupdatesthatwerepassedinthepropagationprocess.

CPUConcentration:Theapproximateprocessingcost,whichisperformedthroughvalidationoperations.

MemoryUtilization:Peakmemoryuseduringroutepropagation.

Security Effectiveness: Percentage of legitimate routes that are accepted and the routing of malicious routes that areblocked.

CPUandmemorymeasurementsareconsideredproxiesforresourceutilization,providinginsightintowhethera protocolisscalablethroughhardware-specificbenchmarks.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

6.4 Performance Results and Lightweight Design Justification

ThispartpresentstheresultsoftheperformanceevaluationofthesuggestedL-SBGPframework.Itexplainswhyit can be considered lightweight compared to classic BGP and BGPsec, a typical cryptography-heavyweight secure routingprotocol.

The performance results of the control-plane simulation using Google Colab are summarized in the table below underthesamenetworkconditions.Themetricsusedtoevaluateitareconvergencetime,control-planemessage overhead,proxyresourceutilization,andsecurityeffectiveness.

ThefindingsshowthatL-SBGPimposesminimalperformanceoverheadcomparedtostandardBGP.Inparticular, convergence time increases slightly due to lightweight route validation, and there is a slight increase in control message overhead from the extra filtering operations. Nevertheless, these increases are pace-limited and subsecond,whichisreasonableforISP-scaleroutingconditions.

L-SBGP substantially increases CPU and memory consumption only in terms of resource usage. This fact proves that the hash-based validation mechanism avoids the high computational cost of public-key cryptography. In contrasttoBGPsec,whereper-hopdigitalsignatureverificationisperformedoneachroutingupdate,L-SBGPrelies on a single lightweight hash calculation and anomaly-sensitive filtering. Consequently, the computational cost growswiththenumberofupdates,notexponentiallywiththelengthofthepath.

The effectiveness results in the field of security also indicate the benefits of the suggested solution. Although typical BGP will accept most poorly intended routing announcements, L-SBGP suppresses the vast majority of maliciousprefixhijacks,reducingthemtothebareminimum.EventhoughBGPsecoffersalmostfullprotection,it comes at the cost of much greater convergence delays, increased processing overhead, and greater operational complexity.

In general, the results suggest that L-SBGP at the end of the day offers a compromise between security and efficiency. L-SBGPmeets the design requirementof being lightweight, as itdoes not require costly cryptographic algorithms or complex key management, and blocks most malicious paths. The framework provides significant security enhancements over standard BGP, with reduced overhead compared to cryptography-heavy secure BGP variants,andisthereforepracticaltodeployinanISP.

Table 2: Performance Comparison of BGP, L-SBGP, and BGPsec

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056 Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

VIII. Discussion

This systematic literature review (SLR) examined 20 articles on secure, lightweight routing protocols used by Internet Service Providers (ISPs) using the Kitchenham approach, which has gained acceptance in recent years. The constantly increasingscale and security risks of the ISP networks justify the necessity to implement routing protocols that do not onlyprovide high securitybut also do not cause significantcomputational, communication, andenergyburdens.Althoughthetraditionalsecureroutingmeasuresuccessfullysafeguardsthenetworkagainst attack,theperformanceoverheadtheycreatemayoccurinappropriateinhigh-speednetworksoranetworkwitha limited amount of resources [18] [19]. Secure lightweight routing protocols are set to bridge this divide by providing a secure routing protocol that achieves high security levels and optimized efficiency, enabling faster convergence,minimalhardwareload,andloweroperationalcosts.Itisimportanttostudyexistingstandards,their advantages, shortcomings, and spheres of application to guide not only their use in industry, but also further investigation.ThisreviewcomparesthemajorlightweightsecureprotocolsadoptedbyISPs,theirkeyoptimization parameters, and recommends future research paradigms to increase scalability, resilience, and sustainability in real-timenetworkconditions.

RQ1: What are the current secure & lightweight protocols for ISPs, their advantages, disadvantages, and application areas?

A variety of secure, low-overhead routing protocols have been proposed to reinforce Internet Service Providers (ISPs) and reduce computational and communication overheads. Lightweight Secure BGP (L-SBGP) is a combinationofcryptographictechniquesandefficiency,enablingfastconvergenceattheexpenseoflimitedlargescale validation. SoBGP provides strong authentication of origin and path, but deployment is difficult due to its complex key management. Pretty Good BGP (pgBGP) uses trust-based anomaly detection, has low processing requirements,butreliesheavilyonhistoricaldata[20].GoBGPsupportsautomationandintegrationwithSDN,but requires programming skills as a prerequisite. Performance is further optimized through recent lightweight protocols, such as RPKI-based variants of BGPsec, and AI and anomaly-detection methods. Being aware of these strengths and weaknesses enables ISPs to choose protocols that strike the right balance between security, scalability,andresourceutilization.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Comparative Performance Profile of Secure BGP Variants

Figure 5: Comparative Performance Profile of Secure BGP Variants

Figure 6: Comparative Performance Profile of Secure BGP Variants

Figure 7: Comparative Performance Profile of Secure BGP Variants

Table 4: Comparison of Lightweight Secure Routing Protocols for ISPs

Protocol Type Advantages Disadvantages Applications

L-SBGP Hybrid Low overhead, fast convergence Limitedlarge-scalevalidation Medium-sizeISPs

SoBGP Cryptographic Origin&pathvalidation Highdeploymentcomplexity Nationalbackbones

© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1750

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Protocol Type Advantages Disadvantages Applications

pgBGP Trust-based Anomalydetectionviahistory Storage-intensive Monitoringsystems

GoBGP Extensible API-basedautomation

Requires programming expertise Dynamic policy control

RQ2: What key design parameters & optimization techniques are employed to reduce computational, communication, and energy overhead?

Keyperformanceindicators(KPIs)areusedtoevaluatetheefficiency,scalability,andsustainabilityoflightweight, secureroutingprotocolsdesignedfordeploymentinISPs.Convergencetimetostabilizeroutingtables,CPUusage, protocol overhead, andenergyefficiencyare the mostrelevantparameters, respectively, interms of howquickly routingtablesstabilizewhenthetopologychanges,howmuchrouterprocessingisrequired,theadditionalcontrol traffic, and the energy consumption costs in large ISP domains. Such parameters are best optimized to minimize downtime,reducecongestion,andsustainoperationswithoutcompromisingsecurity[21].Eachofthementioned protocols,includingL-SBGP,BGPsec,soBGP,andhybridanomaly-detectionmodes,hasslightlydifferentstrengths in these KPIs. Given the need for high security and lightweight performance, ISPs can consider routing solutions thatsupportstabilityandresilienceinhigh-speed,resource-constrainedenvironments.

RQ3: What future directions are recommended for lightweight secure ISP routing?

There havebeenrecentadvancesinthedevelopmentof lightweightsecureroutingprotocols for Internet Service Providers (ISPs), as argued in this paper. Future emergencies need to incorporate machine-learning-based adaptive anomaly detection that would allow routing systems to leverage traffic patterns and respond rapidly to evolving attacks with minimal computational burden. Lightweight cryptographic primitives should be used to provide strong security with minimal resource utilization, especially in high-speed ISP backbones [22][23]. Dynamicpathoptimizationisalsoworthpursuingtoachievegreaterresilienceandservicequalityduringfailures, congestion, or changing network conditions. Moreover, energy-saving TSP algorithms are needed to reduce operating costs and enable sustainable large-scale solutions. Last but not least, multi-objective optimization models will be recommended to optimize security, availability, energy efficiency, and scalability. Collectively, the strategies have the potential to make ISP routing protocols in the future robust, effective, and capable of accommodatingemergingchallenges[24][25].

IX. Conclusion and Future Work

This systematic literature review studied secure lightweight routing protocols deployed by Internet Service Providers (ISPs) and their characteristics, including benefits and limitations, areas of application, and the most significant performance parameters. Following Kitchenham's approach, the present study reconsidered peerreviewed articles published between 2020 and 2025 in IEEE Xplore, ACM Digital Library, ScienceDirect, and SpringerLink. The results showed a wide variety of designs, cryptographic, trust, anomaly-detection, and hybrid onesthatstrivetooffersecuritytointer-domainroutingwithlimitedoverheadsoncomputational,communication, and energy. L-SBGP, SoBGP, pgBGP, and GoBGP protocols have demonstrated varying levels of efficiency, scalability, and deployability, with performance frequently tested for convergence time, CPU utilization, protocol overhead,andenergyconsumptionasthemajorconcerns.Recentprogresshasbeenmade,butissuesremainwith

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

scalingoutISP-widedeploymentsusingamixed,high-trafficarchitecture.Inthesecaseswherebothperformance andhigh-levelsecurityareparamount,thatisamust.

Furtherstudycouldfocusondevelopingcombinedmodelsthatintegratelightweightcryptographicprotocolswith adaptivemachine-learning-basedanomalydetectiontoenhancesecurityresilienceandresponsivenesstoevolving threats. Optimization models that balance security, latency, scalability, and energy efficiency are necessary to addressthewiderangeofoperationaldemandsofmodern-dayISPs.

Multi-Objective Optimization Model for Lightweight Secure BGP Design

min (αTconv + βCPU + γOproto)

subjectto:

Where:

 representsroutingconvergencetime,

 denotesprocessorutilization,

 istheprotocoloverhead,

 areweightingfactorsreflectingISPpriorities,and

 Threshold representstheminimumacceptablesecuritylevel.

Moreover,thestudiesshouldalsofocusonpractical,significanttestingofthesuggestedsolutionstomeasuretheir performance under heavy traffic and with routing table scaling. Further enhancements can also be achieved by exploring dynamic path optimization, incremental deployment models, and energy-aware routing strategies to improve resilience and sustainability. With these strategies coming into consensus, a clear roadmap is now possible for implementing next-generation Lightweight Secure BGP (L-SBGP) solutions that can support high securityandoperationalefficiencyacrossavarietyofISPinfrastructures.

References

[1] Servillo, S., Spadaccino, P., Cuomo, F., & Luciani, F. (2024, June). Autonomous systems risk level in the routeserver infrastructure of an internet exchange point. In2024 IFIP Networking Conference (IFIP Networking)(pp.95-103).IEEE.

[2] Ali,H.,Abouelatta,M.,&Youssef,K.Y.(2025).DynamicConnectivityHub:MultipleISPsSmartAggregation forOptimizedIoTConnectivity.IEEEAccess

[3] Hussain, M. Z., & Hanapi, Z. M. (2023). Efficient secure routing mechanisms for the low-powered IoT network:Aliteraturereview.Electronics,12(3),482.

[4] Zhang,H.,Jia,X.,&Chen,C.(2025).DeepLearning-BasedReal-TimeDataQualityAssessmentandAnomaly Detection for Large-Scale Distributed Data Streams.International Journal of Medical and All Body Health Research,6(1),1-01.

© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1752

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056 Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

[5] Tian,Y. C., & Gao, J. (2023). Networkrouting architecture. InNetwork analysis and architecture(pp. 221273).Singapore:SpringerNatureSingapore.

[6] Islam, M. S., Rahman, M. A., Bin Ameedeen, M. A., Ajra, H., Ismail, Z. B., & Zain, J. M. (2024). BlockchainEnabled Cybersecurity Provision for Scalable Heterogeneous Network: A Comprehensive Survey.CMESComputerModelinginEngineering&Sciences,138(1).

[7] Motaali,S.,deVergara,J.E.L.,&DePedro,L.(2025,June).Real-TimeAnomalyDetectioninBGP:Challenges, IPv6Considerations,andMachineLearningOpportunities.In2025IEEE11thInternationalConferenceon NetworkSoftwarization(NetSoft)(pp.380-383).IEEE.

[8] Saeed, M. M. (2025). An AI-Driven Cybersecurity Framework for IoT: Integrating LSTM-Based Anomaly Detection,ReinforcementLearning,andPost-QuantumEncryption.IEEEAccess.

[9] Goulart, A., Chennamaneni, A., Torre, D., Hur, B., & Al-Aboosi, F. Y. (2022). On wide-area IoT networks, lightweightsecurityanditsapplications apracticalreview.Electronics,11(11),1762.

[10] Dahrouj,H.,Alghamdi,R.,Alwazani,H.,Bahanshal,S.,Ahmad,A.A.,Faisal,A.,...&Shamma,J.S.(2021).An overviewofmachinelearning-basedtechniquesforsolvingoptimizationproblemsincommunicationsand signalprocessing.IEEEAccess,9,74908-74938.

[11] Hussain, M. Z., & Hanapi, Z. M. (2023). Efficient secure routing mechanisms for the low-powered IoT network:Aliteraturereview.Electronics,12(3),482.

[12] Waisi,A.,&Ali,Z.(2023).OptimizedMonitoringandDetectionofInternetofThingsresource-constrained CyberAttacks.

[13] Hussain, M. Z., & Hanapi, Z. M. (2023). Efficient secure routing mechanisms for the low-powered IoT network:Aliteraturereview.Electronics,12(3),482.

[14] Furuness, J.,Morris,C.,Wang, B., Morillo, R., Herzberg, A., &Kasiliya,A. (2025).SecuringBGPASAP:ASPA andotherPost-ROVDefenses.

[15] Nayak,P.P.SURVEYONSECURITYISSUESINCLOUDCOMPUTING.

[16] Ali, H. (2024). M. Dynamic Fast Convergence Improvement using Predictive Network Analysis.Int. J. Comput.Digit.Syst,16,1-16.

[17] Mohsin, A. H. (2022). Optimize routingprotocol overheads inMANETs:challenges andsolutions: a review paper.WirelessPersonalCommunications,126(4),2871-2910.

[18] Ekler, P., Levendovszky, J., & Pasztor, D. (2022). Energy-aware IoT routing algorithms in a smart city environment.IEEEAccess,10,87733-87744.

[19] Pathak,A.,Al-Anbagi,I.,&Hamilton,H.J.(2022).AnadaptiveQoSandtrust-basedlightweightsecurerouting algorithmforWSNs.IEEEInternetofThingsJournal,9(23),23826-23840.

[20] Hussain, M. Z., & Hanapi, Z. M. (2023). Efficient secure routing mechanisms for the low-powered IoT network:Aliteraturereview.Electronics,12(3),482.

© 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1753

[21] Vishwakarma, L., Nahar, A., & Das, D. (2022). LBSV: Lightweight blockchain security protocol for secure storageandcommunicationinSDN-enabledIoV.IEEETransactionsonVehicularTechnology,71(6),59835994.

[22] Wan,T.,Kranakis,E.,&vanOorschot,P.C.(2005,February).PrettySecureBGP,psBGP.InNDSS.

[23] Wright, A. K., Kinast, J. A., & McCarty, J. (2004, June). Low-latency cryptographic protection for SCADA communications. In International Conference on Applied Cryptography and Network Security (pp. 263277).Berlin,Heidelberg:SpringerBerlinHeidelberg.

[24] Butler, K., Farley, T. R., McDaniel, P., & Rexford, J. (2009). A survey of BGP security issues and solutions. ProceedingsoftheIEEE,98(1),100-122.

[25] Caschetto, R. (2024). Anintegrated Webplatform for remotecontrol andmonitoringofdiverse embedded devices: A comprehensive approach to secure communication and efficient data management (Doctoral dissertation,PolitecnicodiTorino

AUTHORS PROFILE

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056 Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072 © 2026, IRJET | Impact Factor value: 8.315 | ISO 9001:2008 Certified Journal | Page1754

Steve Barongo Mong’are is a Master of Science (MSc) student in Computer Science at Murang’a University of Technology, Kenya. He graduated in 2022 with a Bachelor’s degree in Computer Science. His research interests include computer networks, BGP security, and the design of lightweight routing protocolsforISPenvironments.

Stephen T. Njenga is aLecturer intheSchoolofComputingandInformationTechnologyat Murang’a University of Technology, Kenya. He holds a Ph.D. in Information Systems and an M.Sc. in Computer Science from the University of Nairobi and a B.Sc. in Computer Science from Egerton University. His research interests include machine learning, intelligentagents, mobile andcollaborative learning, and distributedledgertechnology.

Daniel K. Makupi is a Lecturer in Computer and Network Security at Murang’a University of Technology, Kenya. He holds a Ph.D. in IT Security and Audit, an M.Sc. in IT, and a BMIT, all from Kabarak University. His research focuses on cybersecurity in emerging technologies such as IoT, blockchain,and5G,withexpertiseinpenetrationtestinganddecentralizedapplications.

Peter Maina Mwangi is a Lecturer in Computer and Network Security at Mama Ngina University College, Kenya. He holds a Ph.D. in Network and Security, an M.Sc. in Data Communication from KCA University, and a B.Sc. in Computer Science from Busoga University. His research interests include ComputerNetworks,Security,andArtificialIntelligence

Turn static files into dynamic content formats.

Create a flipbook
A Systematic Literature and Expert-Based Analysis of Parameters Influencing Lightweight Secure Borde by IRJET Journal - Issuu