close

Choose Your Shared Hosting Plan

Choose Your Reseller Hosting Plan

Choose Your VPS Hosting Plan

Choose Your Dedicated Hosting Plan

Widespread BGP ORIGIN attribute rewriting is steering Internet traffic—researchers urge scrubbing and policy fixes

Widespread BGP ORIGIN attribute rewriting is steering Internet traffic—researchers urge scrubbing and policy fixes

Widespread BGP ORIGIN attribute rewriting is steering Internet traffic—researchers urge scrubbing and policy fixes

Discover how BGP ORIGIN attribute rewriting is impacting Internet traffic and why experts are calling for urgent policy changes and scrubbing solutions.

Border Gateway Protocol (BGP) remains the Internet’s routing backbone, but new measurements indicate that a

Frequently Asked Questions

What does the BGP ORIGIN attribute do, and why does rewriting it matter?

The ORIGIN attribute indicates how a route was originally learned (e.g., from an IGP vs. redistribution) and helps network operators judge route authenticity and stability. If it is rewritten, automated filters and route-validation logic can be misled, causing traffic to follow unexpected paths or fail security checks, even when the IP prefix itself hasn’t obviously changed.

How can widespread BGP ORIGIN rewriting happen in practice?

ORIGIN rewriting can occur when networks manipulate route advertisements between peers—intentionally, due to misconfiguration, or through intermediary systems that reoriginate or repackage routes. Common scenarios include route-maps, policy engines, transit arrangements, route reflectors, and automated tooling that normalizes attributes without preserving original semantics.

What does “steering Internet traffic” mean in this context?

Steering refers to influencing how other networks select routes. Even without changing the prefix, altering ORIGIN can affect routing preference decisions, trigger different filtering behavior, or change how downstream systems interpret the route. As a result, traffic may be shifted toward particular upstreams, potentially impacting performance, reachability, or security posture.

Who is most at risk if ORIGIN rewriting is widespread—end users, ISPs, or both?

The immediate technical risk lands on operators and their routing ecosystems: misvalidated routes, broken policy assumptions, and unexpected path selection across multiple hops. End users are affected indirectly through outages, suboptimal latency, or routing anomalies, especially when the rewriting cascades through transit providers.

What are “scrubbing” recommendations, and what does it look like operationally?

Scrubbing generally means sanitizing or normalizing incoming BGP attributes before they influence routing decisions. In practice, operators may strip or reset inconsistent attributes, apply stricter validation checks, and enforce policy rules that confirm attributes align with expected origin information. This can reduce the chance that manipulated metadata drives path selection.

What “policy fixes” do researchers typically urge to prevent ORIGIN-based manipulation?

Researchers often recommend tightening route-validation and route-policy enforcement so that suspicious or inconsistent ORIGIN values are rejected or heavily constrained. This can include stricter import/export policies, improved change detection for BGP attribute modifications, and broader use of origin validation mechanisms (e.g., RPKI/ROV) where applicable to ensure authenticity signals are consistent.

Post Your Comment

INS-CO
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.