3 ms·
Wikipedia article: https://en.wikipedia.org/wiki/BGP_hijacking https://en.wikipedia.org/wiki/BGP_hijacking
by duality 8y ago
Wikipedia article: https://en.wikipedia.org/wiki/BGP_hijacking https://en.wikipedia.org/wiki/BGP_hijacking
- sgc 8y agoThe article mentions there are mitigations to this type of attack available. Does anyone know of how an individual user could (practically) reduce their exposure to this type of attack?
- lgierth 8y agoA typical mitigation at the ASN level is to have allowlists of exactly which prefixes your downstsream ASN is expected and allowed to announce. I don't recall the name of this technique, and it's somewhat widely deployed, but definitely far from widely enough to secure Internet routing. Individual end users don't have much of a chance to avoid BGP hijacking. You could continuously run traceroutes to your destination network, but then that gives you not much guarantee that individual TCP connections will take the same route as those ICMP packets.
- gruez 8y agoBy using encryption. That way if such attack occurs, the only negative effects is downtime, rather than data exposure.
- altmind 8y agoEncryption does not help BGP hijacks at all. You need to filter the accepted upstream routes. But filtering ultimatively defeats the purpose of BGP - route learning is no longer fully dynamic and need some manual approvals.
- vinay_ys 8y agoThe IP you normally would have communicated with is among the hijacked IPs, then you have exposure. The data you send to such IP is ending up in the hijacker's hands. As an end user, your only defense is to use end-to-end authenticated encryption between you and your intended other end-point. The authenticated part is very critical in this case.