JALURI 17,453 SUMMARIES / 50 SOURCES
SEARCH LAST PASS 07:00 ATOM

Beyond origin validation: Four classes of routing attack nobody Is validating

RPKI has significantly improved protection against prefix hijacking, but a broader review of BGP attacks shows that four attack classes remain unaddressed by cryptographic validation and still depend on local filtering, static limits, and reactive mitigation.

MAIN POINTS
  1. RPKI has delivered real progress against prefix hijacking.
  2. A full BGP attack mapping reveals multiple threat classes beyond hijacking.
  3. Four attack types fall completely outside cryptographic validation.
  4. Those gaps are managed through local filters, static thresholds, and reactive response.
TAKEAWAYS
  1. Cryptographic defenses solve only part of the BGP security problem.
  2. Prefix hijacking is better protected than other routing attacks.
  3. Operational controls still matter for attacks RPKI cannot validate.
  4. BGP security requires layered defenses, not just cryptographic trust.
READ THE ORIGINAL