{"id":34008,"date":"2026-07-28T15:50:09","date_gmt":"2026-07-28T15:50:09","guid":{"rendered":"https:\/\/blog.lacnic.net\/?p=34008"},"modified":"2026-07-28T18:37:59","modified_gmt":"2026-07-28T18:37:59","slug":"origin-validation","status":"publish","type":"post","link":"https:\/\/blog.lacnic.net\/en\/origin-validation\/","title":{"rendered":"Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">By <a href=\"https:\/\/blog.lacnic.net\/en\/author\/flavio-luciani\/\">Flavio Luciani<\/a>, CTO at Namex<br>Contributors:\u00a0Stefano Servillo, Pietro Spadaccino, Marco Centenaro, Massimiliano Rossi, Monica Scannapieco, Francesca Cuomo, Antonio Prado<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>RPKI has made real progress against prefix hijacking. But when you map every known class of BGP attack against the defences that exist, four of them turn out to sit entirely outside cryptographic validation \u2014 handled with local filters, static thresholds and reactive response.<\/em><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Ten seconds in May<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On 20 May 2025, a BGP UPDATE carrying a corrupted Prefix-SID attribute \u2014 optional, transitive, attribute code 40 \u2014 was originated by an AS in the Asia-Pacific region. What happened next was not a hijack and not a leak.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cisco IOS-XR and Nokia SR-OS did what RFC 7606 says: they discarded the malformed attribute and moved on. Juniper\u2019s JunOS passed the message along intact. Arista routers that received it responded by resetting their BGP sessions. Route servers at several IXPs relayed the attribute onward without filtering it. Within ten seconds the global routing system saw more than 150,000 updates, and sessions flapped at Starlink, Disney, Zscaler and ByteDance among others. Arista changed the behaviour in EOS 4.28.11 and later releases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nothing that RPKI validates was violated at any point in that chain. Ask an operator to classify the event and you get a shrug: not a hijack, not a leak, \u201csomething with an attribute\u201d. That is a reasonable proxy for how much attention this class of problem has received.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That gap was one of the starting points for a survey we have just published in <em>IEEE Communications Surveys &amp; Tutorials<\/em>, which revisits the open questions posed in Huston, Rossi and Armitage\u2019s 2011 routing security survey and asks what has actually changed in fifteen years. This article is about the part of the answer that surprised us.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Four macro-categories<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We ended up with a taxonomy of four macro-categories and eight micro-categories. The contribution is not new attack notions \u2014 most of these distinctions already exist in RFCs and in operational practice \u2014 but a single structure with consistent naming, so that every class can be systematically mapped onto the defences that address it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Route Manipulation<\/strong> \u2014 unauthorised modification of prefix or path information. Prefix hijack (PRH) in its complete, incomplete, interception and abusive variants; AS_PATH manipulation (ASM) covering poisoning, forged origin injection, path shortening and path extension.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Routing Consistency<\/strong> \u2014 attacks on the stability of the table rather than its contents. State volatility (VOL): disruptive flapping, flooding through oscillation, amplified churn injection, delayed convergence. Prefix deaggregation (DEG): malicious, careless, exploitative, and the fragmentation flood.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Policy Violation<\/strong> \u2014 routing leaks (RLK) in the four directions defined in RFC 7908, and policy manipulation (POL) via Local Preference, MED, AS_PATH length and selective propagation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Session-based<\/strong> \u2014 attribute-based session reset (ATR): malformed optional transitive attribute injection, vendor-specific attribute exploitation, error-handling policy abuse. This is where the May 2025 event lives.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Where the coverage actually is<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Laying the defences over that structure produces a lopsided picture that is easy to miss when you evaluate any single mechanism on its own.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>PRH<\/strong> is the success story, with caveats. IRR and RPKI provide origin validation, and ROA coverage keeps climbing. But coverage is not enforcement: a longitudinal study across more than 28,000 ASes found that 36.2% do not implement ROV at all, and only 12.3% achieve full protection. Permissive maxLength widens the attack surface rather than narrowing it \u2014 hence RFC 9319. And abusive hijacking of unannounced space remains entirely feasible where objects aren\u2019t maintained.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ASM<\/strong> is partially addressed in principle and barely at all in practice. BGPsec exists, is implemented, and is essentially undeployed: a single non-adopting AS in the path strips the security information, which makes partial deployment close to worthless.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>RLK<\/strong> is where the most encouraging movement is. ASPA objects have been publishable in RIR repositories since December 2025 \u2014 1,314 of them registered at the time of writing \u2014 and analysis suggests that deployment by strategically positioned ASes could cut the number of ASes affected by leaks by up to 96%. The OTC attribute and the Down Only community, both building on the roles defined in RFC 9234, could suppress over 98% of multi-hop leaks if adopted selectively across well-connected Tier-1 and Tier-2 networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>VOL, DEG, POL and ATR<\/strong> have no cryptographic answer at all. Not a partially deployed one \u2014 none. They are addressed with operational hardening, control-plane policing, max-prefix limits, prefix-length filters, policy hygiene, robust error handling, and attribute filtering at route servers. All of these are local, reactive, and unverifiable by the party that suffers the consequences. There is no equivalent of \u201ccheck the ROA and drop invalid\u201d, no global state anyone can query. When an operator asks whether they are protected against a fragmentation flood from a peer, the honest answer is: you have a max-prefix limit and a hope.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Why the uncovered classes matter more than they used to<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two things have shifted the risk profile.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first is IPv6 arithmetic. Deaggregation abuse in IPv4 is bounded by what the attacker actually holds. In IPv6 it isn\u2019t: within a single \/29, up to 524,288 distinct \/48s can be generated and announced. The global IPv6 BGP table currently holds around 219,000 entries. One allocation, one router, and the table more than doubles. The defence \u2014 a static max-prefix threshold \u2014 also breaks legitimate growth if set too tight, which is precisely why operators set it loosely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second is that the partial success of origin validation redistributes attacker attention. As ROV enforcement grows, the marginal return on hijacking a prefix falls and the marginal return on the classes nobody validates rises. That is not a claim about anyone\u2019s intentions; it is the ordinary economics of a control that covers one thing well.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>The four questions still open after fifteen years<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Revisiting the 2011 open questions in light of the above, four remain live:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Routing information versus forwarding state.<\/strong> Can a relying party validate not only that the AS_PATH in an UPDATE matches the path the advertisement travelled, but that the network\u2019s actual forwarding state is aligned with it? Every path-validation mechanism, ASPA and BGPsec included, secures the control plane and says nothing about where packets actually go. Proposals like FC-BGP and SBAS attempt to bridge this, and both remain experimental. This is the most technically difficult open problem in the field.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. The partial deployment problem.<\/strong> If a comprehensive framework is proving undeployable, can a less comprehensive one deliver acceptable outcomes? The evidence says yes, and it also says that effectiveness depends on operator policy: work surveying 100 operators found that partial path validation protects well when policies prefer secure routes, and much less well when they prefer short ones. Partial deployment should be the baseline design assumption for new proposals, not the degraded case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Improving what already exists.<\/strong> Computational cost is no longer the main obstacle it was in 2011 \u2014 modern routers can carry the crypto. Operational complexity is. Managing ROAs, IRR records, ASPA relationships and certificates is a real burden, disproportionately so for smaller networks with limited staff. Proposals like Signed Prefix Lists, which replace permissive maxLength with explicit enumeration of intended announcements, are interesting precisely because they trade a little more maintenance for a lot less ambiguity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Auxiliary tools.<\/strong> Given that protocol-level security is incomplete and will stay incomplete, monitoring and risk assessment carry more weight than their status as \u201ccomplementary\u201d suggests. ARTEMIS, ROSE-T, origin-change detection systems, and risk scoring derived from IXP route server RIBs all provide value without requiring changes to BGP or coordination across ASes. Their effectiveness, though, depends entirely on the quality of IRR records, RPKI repositories and AS relationship data \u2014 which are inconsistently maintained. Improving those datasets is a prerequisite for everything else.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>What the last fifteen years taught us<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Three observations that cut across all of this, and that we think are worth arguing about:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Deployable beats optimal, consistently.<\/strong> S-BGP, soBGP and psBGP offered stronger guarantees than anything deployed today and went nowhere. RPKI, IRR and now ASPA gained traction because they can be adopted incrementally. In inter-domain routing, \u201cgood enough and deployable\u201d wins every time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Universal adoption is not a realistic assumption<\/strong>, and designs that require it have a poor track record.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The costs are individual and the benefits are collective<\/strong>, which is the classic collective action problem and the reason well-designed mechanisms stall. This is where institutional levers matter \u2014 NIS2, the Digital Networks Act proposal, national strategies \u2014 though their effectiveness depends on enforcement and compliance monitoring that remains uneven across jurisdictions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>An invitation to disagree<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The part we are least confident about is the boundary between attack and accident. Almost every incident in the four uncovered classes has an innocent explanation available: a misconfigured redistribution, a script that ran twice, a vendor bug. That ambiguity is exactly why these classes are under-studied \u2014 it is hard to build a threat model around events you cannot attribute. It may also mean we are overstating the risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We would rather be corrected on that by people who run networks than be right about it in a journal. If your operational experience says the max-prefix limit is fine, or that RFC 7606 compliance is now good enough, that is the conversation we are hoping to start.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>\u201cSurvey on Internet Routing Security: Stakeholder Interests, Current and Future Research Directions\u201d is open access under CC BY 4.0 in IEEE Communications Surveys &amp; Tutorials \u2014 DOI: 10.1109\/COMST.2026.3714569. The work is a collaboration between Sapienza University of Rome, Namex (Rome IXP) and the Italian National Cybersecurity Agency (ACN).<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Flavio Luciani, CTO at NamexContributors:\u00a0Stefano Servillo, Pietro Spadaccino, Marco Centenaro, Massimiliano Rossi, Monica Scannapieco, Francesca Cuomo, Antonio Prado RPKI has made real progress against prefix hijacking. But when you map every known class of BGP attack against the defences that exist, four of them turn out to sit entirely outside cryptographic validation \u2014 handled [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":34005,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[919],"tags":[1280],"archivo":[1345,1451],"taxonomy-authors":[1437],"tipo_autor":[],"class_list":["post-34008","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-routing","tag-routing","archivo-editions","archivo-highlights-2023","taxonomy-authors-flavio-luciani"],"acf":{"author":"","related_notes":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>LACNIC Blog | Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.lacnic.net\/en\/origin-validation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"LACNIC Blog | Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating\" \/>\n<meta property=\"og:description\" content=\"By Flavio Luciani, CTO at NamexContributors:\u00a0Stefano Servillo, Pietro Spadaccino, Marco Centenaro, Massimiliano Rossi, Monica Scannapieco, Francesca Cuomo, Antonio Prado RPKI has made real progress against prefix hijacking. But when you map every known class of BGP attack against the defences that exist, four of them turn out to sit entirely outside cryptographic validation \u2014 handled [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.lacnic.net\/en\/origin-validation\/\" \/>\n<meta property=\"og:site_name\" content=\"LACNIC Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/facebook.com\/lacnic\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-28T15:50:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-28T18:37:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/07\/red-bgp-incidente-enrutamiento-seguridad.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"680\" \/>\n\t<meta property=\"og:image:height\" content=\"330\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Gianni\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@lacnic\" \/>\n<meta name=\"twitter:site\" content=\"@lacnic\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/\"},\"author\":{\"name\":\"Gianni\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/person\\\/1338d9cfdb0137e8bc5581f3771f39ab\"},\"headline\":\"Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating\",\"datePublished\":\"2026-07-28T15:50:09+00:00\",\"dateModified\":\"2026-07-28T18:37:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/\"},\"wordCount\":1556,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/red-bgp-incidente-enrutamiento-seguridad.jpg\",\"keywords\":[\"Routing\"],\"articleSection\":[\"Routing\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/\",\"name\":\"LACNIC Blog | Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/red-bgp-incidente-enrutamiento-seguridad.jpg\",\"datePublished\":\"2026-07-28T15:50:09+00:00\",\"dateModified\":\"2026-07-28T18:37:59+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/red-bgp-incidente-enrutamiento-seguridad.jpg\",\"contentUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/red-bgp-incidente-enrutamiento-seguridad.jpg\",\"width\":680,\"height\":330,\"caption\":\"Iluminaci\u00f3n cibern\u00e9tica de un mapa de red global sufriendo una falla de enrutamiento BGP con fragmentos flotantes e \u00edcono de escudo protector en el centro.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/origin-validation\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#website\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/\",\"name\":\"LACNIC Blog\",\"description\":\"En el Blog de LACNIC encontrar\u00e1s art\u00edculos t\u00e9cnicos vinculados al desarrollo de Internet en la regi\u00f3n de Am\u00e9rica Latina y el Caribe.\",\"publisher\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog.lacnic.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#organization\",\"name\":\"LACNIC Blog\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/lacnic-blog.svg\",\"contentUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/lacnic-blog.svg\",\"caption\":\"LACNIC Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/facebook.com\\\/lacnic\",\"https:\\\/\\\/x.com\\\/lacnic\",\"https:\\\/\\\/www.instagram.com\\\/lacnic\\\/?hl=es-la\",\"https:\\\/\\\/uy.linkedin.com\\\/company\\\/lacnic\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/lacnicstaff\",\"https:\\\/\\\/www.lacnic.net\\\/podcast\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/person\\\/1338d9cfdb0137e8bc5581f3771f39ab\",\"name\":\"Gianni\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/author\\\/gianni\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"LACNIC Blog | Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.lacnic.net\/en\/origin-validation\/","og_locale":"en_US","og_type":"article","og_title":"LACNIC Blog | Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating","og_description":"By Flavio Luciani, CTO at NamexContributors:\u00a0Stefano Servillo, Pietro Spadaccino, Marco Centenaro, Massimiliano Rossi, Monica Scannapieco, Francesca Cuomo, Antonio Prado RPKI has made real progress against prefix hijacking. But when you map every known class of BGP attack against the defences that exist, four of them turn out to sit entirely outside cryptographic validation \u2014 handled [&hellip;]","og_url":"https:\/\/blog.lacnic.net\/en\/origin-validation\/","og_site_name":"LACNIC Blog","article_publisher":"https:\/\/facebook.com\/lacnic","article_published_time":"2026-07-28T15:50:09+00:00","article_modified_time":"2026-07-28T18:37:59+00:00","og_image":[{"width":680,"height":330,"url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/07\/red-bgp-incidente-enrutamiento-seguridad.jpg","type":"image\/jpeg"}],"author":"Gianni","twitter_card":"summary_large_image","twitter_creator":"@lacnic","twitter_site":"@lacnic","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/#article","isPartOf":{"@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/"},"author":{"name":"Gianni","@id":"https:\/\/blog.lacnic.net\/#\/schema\/person\/1338d9cfdb0137e8bc5581f3771f39ab"},"headline":"Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating","datePublished":"2026-07-28T15:50:09+00:00","dateModified":"2026-07-28T18:37:59+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/"},"wordCount":1556,"commentCount":0,"publisher":{"@id":"https:\/\/blog.lacnic.net\/#organization"},"image":{"@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/07\/red-bgp-incidente-enrutamiento-seguridad.jpg","keywords":["Routing"],"articleSection":["Routing"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blog.lacnic.net\/en\/origin-validation\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/","url":"https:\/\/blog.lacnic.net\/en\/origin-validation\/","name":"LACNIC Blog | Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating","isPartOf":{"@id":"https:\/\/blog.lacnic.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/#primaryimage"},"image":{"@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/07\/red-bgp-incidente-enrutamiento-seguridad.jpg","datePublished":"2026-07-28T15:50:09+00:00","dateModified":"2026-07-28T18:37:59+00:00","breadcrumb":{"@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.lacnic.net\/en\/origin-validation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/#primaryimage","url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/07\/red-bgp-incidente-enrutamiento-seguridad.jpg","contentUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/07\/red-bgp-incidente-enrutamiento-seguridad.jpg","width":680,"height":330,"caption":"Iluminaci\u00f3n cibern\u00e9tica de un mapa de red global sufriendo una falla de enrutamiento BGP con fragmentos flotantes e \u00edcono de escudo protector en el centro."},{"@type":"BreadcrumbList","@id":"https:\/\/blog.lacnic.net\/en\/origin-validation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/blog.lacnic.net\/en\/"},{"@type":"ListItem","position":2,"name":"Beyond Origin Validation: Four Classes of Routing Attack Nobody Is Validating"}]},{"@type":"WebSite","@id":"https:\/\/blog.lacnic.net\/#website","url":"https:\/\/blog.lacnic.net\/","name":"LACNIC Blog","description":"En el Blog de LACNIC encontrar\u00e1s art\u00edculos t\u00e9cnicos vinculados al desarrollo de Internet en la regi\u00f3n de Am\u00e9rica Latina y el Caribe.","publisher":{"@id":"https:\/\/blog.lacnic.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.lacnic.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/blog.lacnic.net\/#organization","name":"LACNIC Blog","url":"https:\/\/blog.lacnic.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.lacnic.net\/#\/schema\/logo\/image\/","url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2023\/03\/lacnic-blog.svg","contentUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2023\/03\/lacnic-blog.svg","caption":"LACNIC Blog"},"image":{"@id":"https:\/\/blog.lacnic.net\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/facebook.com\/lacnic","https:\/\/x.com\/lacnic","https:\/\/www.instagram.com\/lacnic\/?hl=es-la","https:\/\/uy.linkedin.com\/company\/lacnic","https:\/\/www.youtube.com\/user\/lacnicstaff","https:\/\/www.lacnic.net\/podcast"]},{"@type":"Person","@id":"https:\/\/blog.lacnic.net\/#\/schema\/person\/1338d9cfdb0137e8bc5581f3771f39ab","name":"Gianni","url":"https:\/\/blog.lacnic.net\/en\/author\/gianni\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/07\/red-bgp-incidente-enrutamiento-seguridad.jpg","jetpack_sharing_enabled":true,"wpml_current_locale":"en_US","wpml_translations":[{"locale":"es_ES","id":34003,"post_title":"M\u00e1s all\u00e1 de la validaci\u00f3n de origen: cuatro clases de ataques de enrutamiento que nadie est\u00e1 validando","slug":"validacion-origen","href":"https:\/\/blog.lacnic.net\/validacion-origen\/"},{"locale":"pt_BR","id":34015,"post_title":"Al\u00e9m da valida\u00e7\u00e3o de origem: quatro classes de ataques de roteamento que ningu\u00e9m est\u00e1 validando","slug":"validacao-origem","href":"https:\/\/blog.lacnic.net\/pt-br\/validacao-origem\/"}],"_links":{"self":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/34008","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/comments?post=34008"}],"version-history":[{"count":3,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/34008\/revisions"}],"predecessor-version":[{"id":34020,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/34008\/revisions\/34020"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/media\/34005"}],"wp:attachment":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/media?parent=34008"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/categories?post=34008"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/tags?post=34008"},{"taxonomy":"archivo","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/archivo?post=34008"},{"taxonomy":"taxonomy-authors","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/taxonomy-authors?post=34008"},{"taxonomy":"tipo_autor","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/tipo_autor?post=34008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}