Prefix Hijack Tool Comaprision

Danny McPherson danny at tcb.net
Thu Nov 13 21:09:45 UTC 2008


On Nov 13, 2008, at 1:05 PM, Todd Underwood wrote:
>
> as such, i don't count it as a hijacking or leak of any great
> significance and wouldn't want to alert anyone about it.  that's why i
> recommend that prefix hijacking detection systems do thresholding of
> peers to prevent a single, rogue, unrepresentative peer from reporting
> a hijacking when none is really happening.  others may have a
> different approach, but without thresholding prefix alert systems can
> be noisy and more trouble than they are worth.

While I agree that this incident didn't appear to much impact
anyone beyond CTBC and their customers (where we very clearly
impacted considerably), I would contend that ANY time anyone
asserts reachability of another ASNs address space the owner
of that space should be alerted.

IMO, if an actual intentional targeted attack were to be launched,
versus, say, the slew of accidental leaks we mostly see, then it
may very well be scoped to some insignificant corner of the Internet,
as close to the targets as possible - that's precisely what I'd do
if I were to launch such an attack....

Now, if the goal is denial of service or a leak, sure, it'll
likely propagate much wider - and be detected much quicker.



-danny




More information about the NANOG mailing list