Knowledgebase

BGP Security and Route Hijacking Print

  • internet, security, troubleshooting, errors, guide, howto, solution, zillionkinghost
  • 0

Protecting routing.

WHAT THE FUNDAMENTAL WEAKNESS IS

The protocol was designed for a trusted environment, and announcements are believed by default.

WHAT A ROUTE HIJACK IS

A network announcing address space it does not hold.

WHAT HAPPENS

Traffic is drawn to the announcing network.

WHY IT WORKS

More specific announcements are preferred, so announcing a smaller portion of someone's space wins.

WHAT CAUSES MOST INCIDENTS

Configuration error, not attack.

WHAT A ROUTE LEAK IS

Routes learned from one peer or provider announced to another, inappropriately.

WHAT THAT CAUSES

Traffic routed through a network that should not carry it, frequently overwhelming it.

WHAT DEFENCES EXIST

Filtering: accepting only expected prefixes from each neighbour

Maximum prefix limits, shutting a session that announces too many Route origin authorisation, cryptographically stating which network may originate a prefix Validation of those authorisations before accepting routes

WHAT INDUSTRY NORMS RECOMMEND

Filtering, origin validation, anti-spoofing, and published contact details.

WHAT TO DO AS A NETWORK OPERATOR

Publish authorisations for your own space, and validate what you accept.

WHAT TO ASK PROVIDERS

Whether they validate.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot