How secure is BGP?

How secure is BGP?

BGP has worked extremely well and continues to the be protocol that makes the Internet work. The challenge with BGP is that the protocol does not directly include security mechanisms and is based largely on trust between network operators that they will secure their systems correctly and not send incorrect data.

What is BGP traffic?

“Border Gateway Protocol (BGP) is a standardized exterior gateway protocol designed to exchange routing and reachability information between autonomous systems (AS) on the Internet. The protocol is often classified as a path vector protocol but is sometimes also classed as a distance-vector routing protocol.”

How is the BGP protocol used in the Internet?

BGP is the routing protocol that makes the internet work. The current revision is BGP v4, and has been in use since 1995. Internet Service Providers (ISPs) are in control of one or many networks, and they use BGP to advertise their networks to their peers by exchanging routing information (internet routes) about the network they control.

Why is BGP vulnerable to routing related attacks?

BGP is especially vulnerable to routing-related attacks especially when ISPs misconfigure their route advertisement. Notable incidents which are not of malicious intents include Pakistan Telecom blocks YouTube, Malaysian ISP blocks Yahoo or Turkish ISP takes over the Internet, etc.

Which is a positive security feature of BGP?

In short, BGP is highly exposed to false route advertisements and there is no plan today to remediate this situation. So it looks pretty bad on a security standpoint. But on the other hand, there are also some positive security aspects in BGP: BGP peering associations tend to be long-lived and static.

What kind of BGP is used in autonomous systems?

Autonomous systems can also use an internal version of BGP to route through their internal networks, which is known as internal BGP, or iBGP for short. It should be noted that using internal BGP is NOT a requirement for using external BGP.