Contents
How can BGP attack be prevented?
Filter Own Prefixes and Accept only Prefixes with Length /24 and Less. Customers do not need to know about the path to their own prefixes so they should filter them. However, filtering the single prefix 199.1. 1.0/24 is not sufficient.
What is Route hijacking?
BGP Route Hijacking, also called prefix hijacking, route hijacking or IP hijacking, is the illegitimate takeover of groups of IP addresses by corrupting Internet routing tables maintained using the Border Gateway Protocol (BGP).
What types of attacks is Border Gateway Protocol BGP susceptible to?
Types of BGP Attacks
- Denial of service. An attacker can black-hole portions of the Internet either by creating false routes or by killing valid ones.
- Sniffing.
- Routing to endpoints in malicious networks.
- Creation of route instabilities.
- Revelation of network topologies.
When does a BGP speaking router get hijacked?
In fact, everyone who has been assigned an AS number or gained access to a BGP speaking router can announce any prefix. A partial BGP hijacking occurs when two origin Autonomous Systems announce an identical IP prefix with the same prefix length.
How does a BGP router accept an IP prefix?
It means that IP prefix announced by a router is accepted by its neighbor by default (except for when the neighbor detects its own AS number in the AS_PATH attribute (BGP loop prevention mechanism)). The IP prefix is then installed into the peer routing table and is advertised to the other BGP peers.
What does it mean when BGP peers trust each other?
BGP peers are explicitly defined with the neighbor command and they trust each other. It means that IP prefix announced by a router is accepted by its neighbor by default (except for when the neighbor detects its own AS number in the AS_PATH attribute (BGP loop prevention mechanism)).
Why is as64502 not routed through customer BGP router?
The configuration prevents customer AS64502 to become transit AS in case of a multihomed connection. As a result, traffic sent from another ASs is not routed through customer but uses a high-speed link of upstream providers instead. The ISP can also configure the AS_PATH filter towards customer BGP router 200.1.1.2.