Architecture, Implementation, and Operations at Production Scale
Introduction: Why BGP Security Is a Systems Problem
Chapter 1: The Internet Routing System and the Security Problem Space
- The Routing Table: Scale, Structure, and Daily Churn
- How a Packet Travels: From Source to Destination Through Autonomous Systems
- The Economic and Political Architecture of the Internet: Customers, Peers, and Transit Providers
- Why BGP Inherently Lacks Security: Design Trade-offs of the 1990s
- Real-World Consequences: A Brief History of Major Routing Incidents
Chapter 2: BGP Protocol Mechanics Relevant to Security
- The BGP Finite State Machine and Session Establishment
- BGP Message Types: Open, Update, Notification, Keepalive
- Path Attributes and Their Security-Relevant Properties
- Route Selection and Path Preference Logic
- IBGP, EBGP, Confederations, and Route Reflectors
Chapter 3: The BGP Threat Landscape
- Prefix Hijacking: Origin Attacks and Traffic Redirection
- Route Leaks: Accidental and Intentional Violation of Routing Policy
- AS-Path Manipulation: Injection, Shortening, and Splicing
- Maximal Prefix Announcements and Exhaustion Attacks
- DoS Against the Routing Control Plane
- BGP Session Hijacking and TCP Exploitation
- Malformed Updates, Route Flapping, and Churn Attacks
- Attribute Manipulation: MED, Local Preference, Communities
- Real-World Incident Anatomy: A Detailed Case Study
Chapter 4: Routing Trust Architecture and Design Principles
- The Routing Trust Problem: What Can We Verify and What Must We Trust?
- Defense in Depth for Internet Routing
- The Validity Spectrum: From Open to Cryptographically Verified
- Least Privilege for Prefix Announcements
- Trust Boundaries Across Organizational Perimeters
- Balancing Security, Availability, and Operational Complexity
Chapter 5: RPKI Cryptographic Architecture
- The RPKI Hierarchy: RIRs, LIRs, and End Entities
- Resource Certificates: Binding Cryptography to IP Addresses and AS Numbers
- Cryptographic Algorithms and Key Management in RPKI
- Route Origin Authorizations: Structure, Semantics, and Max-Length Semantics
- ROA Validation Logic: What “Valid” Actually Means
- Revocation, CRLs, and Manifest Files
Chapter 6: RPKI Repositories, Validators, and RTR Protocol
- RPKI Repositories: RIR Architecture and Availability
- RPKI Validators: How They Build the Trust Anchored View
- The RTR Protocol: Format, Flow, and Behavior
- Running a Validator in Production: Resilience and Redundancy
- Validator Comparison: Routinator, Falcon, BGP Tools RPKI Server
- RTR Client Integration in Major Router Platforms
Chapter 7: Route Origin Validation: Design, States, and Deployment
- ROV State Machine: Valid, Invalid, Not-Found Defined
- Making Routing Decisions Based on ROV State
- ROV Migration Strategies: From Passive Validation to Enforcement
- Handling Not-Found: Policy Choices and Operational Realities
- ROA Coverage Gaps and Their Practical Implications
- Multi-Validator Architectures for ROV Resilience
Chapter 8: IRR, RPSL, and Legacy Route Object Systems
- The Internet Routing Registry History and Purpose
- RPSL Data Model: Routes, Route-Origins, and Route-Set Objects
- Querying IRRs: Whois Protocol, Query APIs, and Batch Retrieval
- IRR-Derived Filtering: How to Use IRR Data for Prefix Filters
- IRR vs RPKI: Complementary Roles in Modern Architectures
- Common IRR Data Quality Problems and Mitigation Strategies
Chapter 9: ASPA: Autonomous System Provider Authorization
- The Problem ASPA Solves: Relationship Validation
- ASPA Data Model: Provider Authorization Records
- ASPA Cryptographic Structure and RPKI Integration
- AS-Path Validation with ASPA
- Deployment Status and Timeline
- Limitations and Remaining Gaps
Chapter 10: BGPsec: Architectural Vision and Practical Reality
- The BGPsec Problem Statement: Securing the AS Path
- BGPsec Protocol: Signed Path Attributes and Key Hierarchies
- BGPsec vs RPKI/ROV: Different Guarantees, Different Trade-offs
- Operational Barriers to BGPsec Adoption
- BGPsec Deployment Status and Pilot Networks
- BGPsec as a Long-Term Goal vs Short-Term Tool
Chapter 11: BGP Communities and Route Attribute Security
- BGP Communities: Standard, Extended, and Large Communities
- Using Communities for Policy Enforcement
- Security Implications of Community-Based Routing
- Community Manipulation: Threats and Defenses
- Vendor-Specific Community Implementations
- Automating Community-Based Policies
Chapter 12: Prefix Filtering, AS-Path Filtering, and Bogon Defense
- Inbound Prefix Filtering: Customer, Peer, and Transit Policies
- Outbound Prefix Filtering and Advertisement Control
- AS-Path Filtering and Regular Expressions
- Bogon Filtering: Reserved, Documentation, and Private Ranges
- Building Filtering Tables from IRR and RPKI Data
- Policy Design Patterns: Safe Defaults and Least Privilege
Chapter 13: Route Stability Controls: Dampening, Max-Prefix, and Limits
- BGP Route Dampening: Mechanism, Parameters, and Trade-offs
- Max-Prefix Limits: Protecting Router Resources
- Rate Limiting BGP Updates
- Per-Peer and Per-Customer Quotas
- Tuning for Stability vs Responsiveness
Chapter 14: Blackholing and Remote-Triggered Blackholing
- Blackhole Routing: Basic Mechanics
- Remote-Triggered Blackholing: Design and Operation
- Standard RTBH: Discard Communities and Null Routes
- Per-Prefix RTBH and Next-Hop Based Blackholing
- Integration with DDoS Mitigation Systems
- Safety and Recovery: Avoiding Accidental Blackholes
Chapter 15: Reference Architectures for Production Environments
- Transit Provider Architecture: Tier 1, Tier 2, and Regional ISPs
- Enterprise Multi-Homing with Dual Transit
- SaaS and Content Provider Architectures
- Cloud and Data Center Routing Security
- IXP Route Server Security
- Managed Service Provider Architectures
Chapter 16: Implementing BGP Security: End-to-End Configurations
- FRRouting: Complete BGP Security Configuration
- BIRD: Security-Focused BGP Daemon Setup
- GoBGP: Programmatic BGP Security
- Cisco IOS-XR: Production BGP Security
- Juniper Junos: Enterprise-Grade BGP Security
- OpenBGPD and Lightweight Deployments
Chapter 17: Automation and Infrastructure-as-Code for Routing Security
- Configuration Management for BGP Policies
- Generating Filters from RPKI and IRR Data
- GitOps for Routing Security
- Safe Deployment: Testing and Rollback Strategies
- Automation with Ansible, Terraform, and Custom Tools
- Preventing Configuration Drift and Unsafe Changes
Chapter 18: Routing Telemetry, Monitoring, and Anomaly Detection
- Monitoring the Global Routing Table
- BGP Telemetry: Streaming Updates and Table Dumps
- Anomaly Detection: Statistical Methods and ML Approaches
- Route Origin Monitoring and Alerting
- Building a Routing Security Dashboard
- Integration with SIEM and SOAR Platforms
Chapter 19: Incident Response: Detecting, Investigating, and Mitigating Routing Attacks
- Detecting a Routing Incident: Early Warning Signals
- Investigation Workflow: Tools, Queries, and Data Sources
- Case Study: Responding to a Prefix Hijack
- Case Study: Diagnosing a Route Leak
- Case Study: Invalid ROA Incident Response
- Communication, Coordination, and Escalation
Chapter 20: Operational Lifecycle and Production Hardening
- ROA Lifecycle Management at Scale
- Key and Certificate Rotation for RPKI
- Change Management for BGP Security Policies
- Testing and Validation Procedures
- Capacity Planning for Routing Infrastructure
- Disasters, Failures, and Recovery Plans
- Auditing, Compliance, and Security Reviews