Duke Research Experiment Disrupts Internet Traffic
alphadogg writes with this excerpt from Network World about an experiment gone wrong which affected a big chunk of internet traffic yesterday morning: "It was kicked off when RIPE NCC (Reseaux IP Europeens Network Coordination Centre) and Duke ran an experiment that involved the Border Gateway Protocol (BGP) — used by routers to know where to send their traffic on the Internet. RIPE started announcing BGP routes that were configured a little differently from normal because they used an experimental data format. RIPE's data was soon passed from router to router on the Internet, and within minutes it became clear that this was causing problems. ... [f]or a brief period Friday morning, about 1 percent of all the Internet's traffic was affected by the snafu, as routers could not properly process the BGP routes they were being sent."
Maybe, yes. BGP has been identified as vulnerable for a long time, and this is further proof. On the other hand, this research is probably motivated by fixing the problem. But the Internet is no longer something you can just shut down or reboot to upgrade; you must operate on a live patient. It does make you wonder, though, if well-intentioned people can do this trying to help, what somebody malicious could do. Hopefully governments will decline to use this as a weapon - like poisoning the ocean.
Any ISP network engineer has some good BGP stories.
For me I was I fighting for over a year to get some of MY blocks back from another provider. They simply continued to announce the routes for them and made it uttererly worthless. It was also fairly horrible to get any upstream traction against the offender.
Eventually, we simply started announcing the routes for those blocks and caused turmoil for those who were using them. It didn't take long to get that issue cleaned up afterwards. Though it was funny because they had asked my guys to stop announcing.
BGP is a bit of a trust relationship, but it isn't the end of world when everything goes to shit.
Admins will get up for their beds and start clearing issues. Things will be sluggish for a bit, but eventually things work out.
"You should always go to other people's funerals; otherwise, they won't come to yours." -- Yogi Berra
Fake it? Not in the last five years!
unless you know of some BGP peers that refuse the standard peering protocol, 1) they are required to only listen to routes from known surrounding peers, 2) will not be listening to what's being advertised by your router unless you have instructed them ahead of time what AS you manage and what prefixes you will be advertising to them.
No. Period, fucking no. Most BGP sessions run between customers and carriers are still basically allowing whatever. Even the big boys basically don't care what you advertise. It would cause too many problems to go and begin filtering, so only regions that seem to have routing DBs (RIPE region) are even remotely participating in this. For the most part, thats a few places here and there, but the carriers will let you do what you want.
Don't believe the hype: BGP is still as weak in public IP as it ever has been. The difference is that if you do decide to hijack someone else's prefixes (don't even include bogons, because the carriers will probably let you advertise those!), everyone will know and you will get your upstream looking at you.