Q: A sophisticated attacker wants to intercept your company's web traffic. Even though your DNS is secure, they manage to physically hijack the routing paths of the internet so traffic destined for your datacenter IP addresses is sent to their servers in Russia. What is this attack called, and what defensive protocol mitigates it?
This is a BGP Hijacking attack. The internet relies on the Border Gateway Protocol (BGP), where networks announce to each other which IP ...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
This is a BGP Hijacking attack. The internet relies on the Border Gateway Protocol (BGP), where networks announce to each other which IP prefixes they own. By default, BGP operates on implicit trust. A malicious ISP can announce to the world that it is the fastest route to your IP space, and global routers will dynamically update and siphon your traffic into the attacker's black hole. The primary defensive mitigation is RPKI (Resource Public Key Infrastructure). RPKI is a cryptographic framework that uses Route Origin Authorizations (ROAs) signed by regional internet registries. When RPKI is enforced, global backbone routers will mathematically verify the cryptographic signature of a BGP announcement against the RPKI authority before accepting the route, causing the attacker's forged announcement to be automatically dropped.
- Immediate Triage: This is a BGP Hijacking attack. The internet relies on the Border Gateway Protocol (BGP), where
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.