Got it

BGP - a network’s lifeline, Secure it! Highlighted

Latest reply: Jan 17, 2022 15:38:56 1047 27 16 0 2

BGP - a network’s lifeline, Secure it!

Few days ago, a large BGP routing leak that occurred disrupted the connectivity for thousands of major networks and websites around the world.

     Although this BGP routing leak occurred in an ISP's autonomous network (AS55410) based in Asia, but it has impacted several companies around the world.

                                             

BGP route leak tweet

Image Credit: Social Microblogging site - George tweet

    Though issue existed for 10 odd minutes, but countless users around the world suffers internet connection problem.

 

BGP not Safe?

Before knowing if Border Gateway Protocol (BGP, a widely adopted protocol for Internet { Internetwork  of networks}), we need to look what it is and risk associated with it.

 

What is BGP? BGP Hijacking & BGP Leaking

BGP

BGP or Border Gateway Protocol is the protocol used to exchange reachability information between  networks and build a “roadmap” of the Internet – simply it is what makes the modern-day internet works.

 

BGP topology

BGP – A protocol for Internet  

Issue with BGP 

        Over the Internet, different nodes (autonomous systems) advertise the pool of IPs (Internet Protocol) they manage and the traffic they are able to route and every network has a unique number allocated known as Autonomous System Number (ASN), used as a representation of that network.

 

BGP is fragile and does not embed any security protocols, without additional controls, this information of route accepted with mistakes can be intercepted or can be blackholed altogether.


Hijacking of BGP

BGP route hijacking occurs when a malicious entity manages to "falsely advertise" to other routers. During this, destined to your network is rerouted to a third party and stays there, creates trouble on the Internet and lead to delays, traffic congestion, or total outages.

BGP hijack

BGP Hijacking

Image Credit: DE-CIX website


    In the above figure, BGP routes are hijacking and routing towards the wrong network rather than going to the destination network.


BGP Leaking or BGP Route leak

In route leaking, traffic of your network is redirected to wrong path/network & likely flow in an inefficient way, which could lead to increased network latency and packet loss. Nevertheless, it will reach your network almost certainly if there is no critical network congestion due to some reason.


BGP leak

BGP Hijacking

Image Credit: https://laptrinhx.com/


In the above figure, Route is taking the longer path and  reaching to destination (AS1) causing delay and service degradation  


Leaking Vs Hijacking 

The two main differences between both are described as:


Routes redirected through wrong ASNs/links (Route leaks), described as types 1-4 RFC 7908;

Routes redirected to wrong ASNs (Hijack), described as types 5 and 6 RFC 7908.


Securing Network by securing BGP

        Security of network is cricuical for maintaining network reliability, it is not a one-time task but an ongoing process, which should be continue 

Some common safeguards that companies can use to protect against BGP leaks:

 

  1. Deploy RPKI

  2. Follow MANRS religiously.

  3. Setting MAX PREFIX Limit

  4. Configure Filters

 

RPKI

Resource Public Key Infrastructure (RPKI) authenticates BGP route announcements, currently, we have 800k+ routes on the Internet, it is impossible to check them manually. RPKI is a security framework method that associates a route with an autonomous system. It uses cryptography in order to validate the information before being passed onto the routers.

BGP RPKI

RPKI – In action

Image Credit: https://blog.cloudflare.com/rpki/ 

MANRS 

Mutually Agreed Norms for Routing Security is a global initiative of network and IXP operators that provides crucial fixes to mitigate the most common threats to the Internet routing system.

It prevents basic exploits that rely on the insecurities of BGP. ISPs, Internet exchanges, cloud service providers, content delivery providers, research and education networks, and other large networks need to take action to implement MANRS guidelines for overall network security.

BGP MANRS

MANRS

Image Credit:  https://www.manrs.org/

Max Prefix

It automatically disables a BGP connection when a downstream network suddenly starts sending an unexpectedly large number of BGP routes, which helps in avoiding issues later.

 

Filters are MUST!

         Autonomous Systems should only announce legitimate routes. Filters need to be built in order to make sure only legitimate routes are accepted. 

Whois database filtering is also a good option as it accepts prefixes only defined in the whois database but takes more time to converge like 24 hours

Bottom Lines

Take care of your BGP's configuration, it will take care of your Network & protect resources.

Complying with MANRS and leveraging RPKI are key steps towards achieving a better network security.

 



Article By: Bashir Ahmed Zeeshan

The post is synchronized to: Author groupBAZ's Author Collection

Good to know.
View more
  • x
  • convention:

IndianKid
Moderator Author Created Apr 23, 2021 06:19:15

Wow BAZ, Really interesting article to read, and thanks for explaining the importance of BGP.
View more
  • x
  • convention:

BAZ
MVE Author Created Apr 23, 2021 12:14:26

Posted by IndianKid at 2021-04-23 06:19 Wow BAZ, Really interesting article to read, and thanks for explaining the importance of BGP.
Glad you liked it. Being a true Network engineer you understands worth of BGP
Thanks for always appreciating BGP - a network’s lifeline, Secure it!-3901135-1
View more
  • x
  • convention:

Saqib123
Saqib123 Created Apr 23, 2021 18:23:36 (0) (0)
 
Saqib123
Saqib123 Created Apr 23, 2021 18:23:52 (0) (0)
 
The content is beneficial.
View more
  • x
  • convention:

BAZ
BAZ Created Apr 23, 2021 21:17:44 (0) (0)
Yes indeed  
BAZ
BAZ Created Apr 23, 2021 21:23:48 (0) (0)
Thanks for liking  
Good topic
View more
  • x
  • convention:

Good
View more
  • x
  • convention:

Interesting issue.
Thanks for sharing!! BGP - a network’s lifeline, Secure it!-3903037-1
View more
  • x
  • convention:

BAZ
BAZ Created Apr 30, 2021 19:48:43 (0) (0)
Obliged Sir.  
andersoncf1
MVE Author Created Apr 25, 2021 02:25:39

Great article my friend. Congrats
View more
  • x
  • convention:

zaheernew
MVE Author Created Apr 30, 2021 09:59:29

Highly useful article
View more
  • x
  • convention:

12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.