Beyond origin validation: Four classes of routing attack nobody Is validating
RPKI has significantly improved protection against prefix hijacking, but a broader review of BGP attacks shows that four attack classes remain unaddressed by cryptographic validation and still depend on local filtering, static limits, and reactive mitigation.
MAIN POINTS
- RPKI has delivered real progress against prefix hijacking.
- A full BGP attack mapping reveals multiple threat classes beyond hijacking.
- Four attack types fall completely outside cryptographic validation.
- Those gaps are managed through local filters, static thresholds, and reactive response.
TAKEAWAYS
- Cryptographic defenses solve only part of the BGP security problem.
- Prefix hijacking is better protected than other routing attacks.
- Operational controls still matter for attacks RPKI cannot validate.
- BGP security requires layered defenses, not just cryptographic trust.