5 ms·
I really have no idea what any of that means, but it sounds interesting and I want to understand it. Where do I start?
by RingwormOne 9y ago
I really have no idea what any of that means, but it sounds interesting and I want to understand it. Where do I start?
- mitchs 9y agoI'd say look up BGP (Border Gateeway Protocol,) but the wiki page buries the important parts, since it describes the protocol state machine and packet format before even attempting to give a high level picture. AS, standing for Autonomous System, is like an ISP's name. BGP spreads routing information by rumor. For example, I start the rumor that I can route to IP addresses in 1.2.3.0/24, and tell my peer ISPs. They tell their peers I told them... etc. To prevent rumors from going in circles, you keep a record of every ISP in the path of spreading the rumor, and call it the AS path. (Otherwise you could never retract the rumor, as it would go in circles. BGP speakers do not accept rumors that they themselves are in the path of. (Except in cases of dirty hacks, but then only a finite number of times.)) This article describes fraudulent AS paths attached to (as I understood it) IP ranges that were legitimately owned by the people advertising them to Hurricane Electric. This is like you telling Hurricane Electric that I (the North Korean ISP) told you that I can route to 1.2.3.0/24, an IP address range you own, even though I told you no such thing and we are not even peers.
- feelin_googley 9y agoRFC 2650 __=$(exec sed -n '/^4.31.198.44 /!d;=;q' /etc/hosts); test ${#__} -gt 0|| echo 4.31.198.44 www.ietf.org >> /etc/hosts http://www.ietf.org/rfc/rfc2650.txt http://www.ietf.org/rfc/rfc2650.txt Avast, NFOrce, etc. can update their BGP routing information with a routing registry probably by just sending an email with some authentication details. Apparently the veracity of provided information is not checked. The information then gets propagated to a shared routing registry database offered to the public for free by a handful of registries via WHOIS. The blog author suggests that the inaccuracies in Maxmind may originate from fake information in WHOIS. http://www.eecs.qmul.ac.uk/~steve/papers/geolocation-ccr-11.pdf http://www.eecs.qmul.ac.uk/~steve/papers/geolocation-ccr-11.... This paper discusses accuracy of GeoIP databases. It concludes they are between 96-98% accurate at the country-level. Maybe the database compilers would use delay measurement for the 2-4% if the inaccuracies follow some pattern, e.g. they are consitently associated with particular countries. Maybe they already use this method. I don't know. The IP addresses in the blog, and the idea of fake VPN exit nodes, were discussed previously: http://blog.trendmicro.com/trendlabs-security-intelligence/a-closer-look-at-north-koreas-internet/ http://blog.trendmicro.com/trendlabs-security-intelligence/a...
- jshap70 9y agothis is quite possibly the least helpful comment you could have made for someone saying a lot of it went above their head