BGP Route Leaks & Hijacks

The internet operates on trust. When a network erroneously claims it is the best path to a destination, traffic follows, resulting in massive black holes or interception.

Historical Major Incidents

A leak occurs when routing policies are misconfigured (e.g., a customer announces their provider's routes to another provider). A hijack is often malicious, claiming space you don't own. RPKI is the primary defense against this.

DateOriginatorVictimImpact
Feb 2008Pakistan Telecom (AS17557)YouTube (AS36561)Attempted domestic censorship leaked globally, taking YouTube offline worldwide for 2 hours.
Apr 2010China Telecom (AS23724)US Govt/Military15% of global internet traffic was routed through China for 18 minutes due to false prefix announcements.
Jun 2015Telekom Malaysia (AS4788)Level 3 (AS3356)TM leaked over 170,000 routes to Level 3, which accepted them, causing severe global slowdowns.
Nov 2018MainOne (AS37282)Google (AS15169)Nigerian ISP leaked routes, dropping Google traffic into China Telecom, causing an hour-long outage.
Oct 2021Facebook (AS32934)Self-InflictedConfig error withdrew Facebook's own routes globally. DNS failed. Facebook disappeared for 6 hours.

Tool: Prefix Specificity Risk Scorer

BGP prefers the most specific route. Check if your IP announcement strategy is vulnerable to a more specific hijack.

The Mechanism of a Leak

A route leak happens when an AS violates Valley-Free routing. For example, if a small ISP buys transit from AT&T and Verizon, it should only announce its own IPs to them. If the ISP accidentally takes the routes it learns from AT&T and announces them to Verizon, Verizon might see that small ISP as a shortcut to AT&T, crushing the ISP's infrastructure with backbone traffic.

FAQ

Can we just filter bad routes?

Yes, but it's hard. Tier 1 networks have hundreds of thousands of customers. Maintaining accurate filter lists (IRR databases) is administratively heavy, leading to stale or permissive filters.