BGP hijack (simulated)¶
⭐ Flagship module.
1. Context & stakes¶
Hijack a prefix in a lab AS mesh - flagship module.
BGP routes the Internet on trust: a router accepts a neighbour's claim to originate a prefix with no built-in proof of ownership. By announcing someone else's prefix, or a more specific one, an AS attracts their traffic and can inspect, drop or reroute it. Real hijacks have blackholed YouTube and rerouted crypto and DNS traffic; RPKI origin validation is the deployed mitigation.
2. Theory¶
BGP glues the Internet together: each Autonomous System advertises the prefixes it originates, and routers prefer the most specific / shortest AS-path. With no built-in origin authentication, an AS that announces a prefix it doesn't own - or a more specific sub-prefix - draws that traffic to itself. RPKI/ROA validates origin to contain it.
3. Attack (PoC)¶
- Prefix / subprefix hijack
- Route leak between ASes
4. Detection¶
Indicators to watch, and the associated IDS rule (see
netlab-ids).
5. Defense¶
- RPKI / ROA origin validation
- max-prefix, AS-path filters
6. Exercise¶
Reproduce in the isolated lab (netns/veth): see lab setup.