Open cardosec

Case 13E28B · Network · L5 Expert

BGP Hijacking and RPKI

Practise as: Deep dive · Interview

Interview questionHow does a BGP prefix hijack work, and what do RPKI and route origin validation actually protect against?

  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. BGP trusts neighbour announcements; longest-prefix match means a more-specific announcement attracts traffic globally
  2. RPKI ROAs bind a prefix and maxLength to an origin ASN; route origin validation marks routes valid, invalid or not-found
  3. ROV only checks the origin: a forged-origin hijack that appends the victim ASN still validates; ASPA and BGPsec target paths
  4. Loose maxLength lets an attacker announce valid-looking more-specifics; keep ROAs tight to the prefixes you announce
  5. Ops: ROAs for all space, customer prefix filtering (IRR, MANRS), and alerting from public collectors on new origins

If the interviewer pushes back

  • A foreign AS starts originating your /22 at 03:00. What can you do in the first hour, and what limits a /24 counter-announcement?
  • Why does ROV deployment by large transit providers matter more than by stub networks?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.