2 ms·
A typical mitigation at the ASN level is to have allowlists of exactly which prefixes your downstsream ASN is expected and allowed to announce. I don't recall t
by lgierth 8y ago
A typical mitigation at the ASN level is to have allowlists of exactly which prefixes your downstsream ASN is expected and allowed to announce. I don't recall the name of this technique, and it's somewhat widely deployed, but definitely far from widely enough to secure Internet routing.
Individual end users don't have much of a chance to avoid BGP hijacking. You could continuously run traceroutes to your destination network, but then that gives you not much guarantee that individual TCP connections will take the same route as those ICMP packets.