Case 13E28B · Network · L5 Expert
BGP Hijacking and RPKI
Practise as: Deep dive · Interview
Interview questionHow does a BGP prefix hijack work, and what do RPKI and route origin validation actually protect against?
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- BGP trusts neighbour announcements; longest-prefix match means a more-specific announcement attracts traffic globally
- RPKI ROAs bind a prefix and maxLength to an origin ASN; route origin validation marks routes valid, invalid or not-found
- ROV only checks the origin: a forged-origin hijack that appends the victim ASN still validates; ASPA and BGPsec target paths
- Loose maxLength lets an attacker announce valid-looking more-specifics; keep ROAs tight to the prefixes you announce
- Ops: ROAs for all space, customer prefix filtering (IRR, MANRS), and alerting from public collectors on new origins
If the interviewer pushes back
- A foreign AS starts originating your /22 at 03:00. What can you do in the first hour, and what limits a /24 counter-announcement?
- Why does ROV deployment by large transit providers matter more than by stub networks?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.