Unexpected Routes: BGP Prefixes Beyond Recommended Practices

The work

AuthorsKhwaja Zubair Sediqi
Editors
Typephdthesis
Year2025
Citekeysediqi2025unexpected

Where it appeared

SchoolSaarland University

Abstract

The Internet is composed of a vast collection of interconnected networks, also known as Autonomous Systems (ASes). ASes use Border Gateway Protocol (BGP) to exchange the reachability information of IP prefixes. The Resource Public Key Infrastructure (RPKI) enhances BGP security by providing cryptographically verifiable objects that confirm the ownership of the IP prefix by an AS. A set of well-documented best practices and guidelines for route announcements governs the Internet’s interdomain routing between ASes. For proper operation of Internet routing, adherence of network operators to the recommended norms and best practices is important. Among these best practices are the recommendations for using prefix lengths up to /24 for IPv4 and up to /48 for IPv6, single origin AS for IP prefix announcement, and registering a single prefix per Route Origin Authorization (ROA) object in RPKI. However, not all network operators follow these recommendations, and instead, their route announcements might be based on their policies, business needs, or technical limitations. Deviating from best routing practices can lead to routing inconsistency, complicate prefix origin validation, and disrupt network performance. This dissertation examines the routing ecosystem for violations of the aforementioned best practices. We define these cases as “unexpected routes” because they represent routes that are less anticipated and remain underexplored in prior research. First, we examine the routing ecosystem of the Internet for IP prefix sizes that are too specific. More precisely, we focus on IP prefixes more specific than /24 in IPv4 (i.e., /25 to /32) and than /48 for IPv6 (i.e., /49 to /128), and we refer to these prefixes as Hyperspecific Prefixes (HSPs). We analyze over eleven years of BGP data from well-known route collector projects to understand the evolution, examine their BGP communities and CIDR sizes to understand the reasons for HSP existence, and the potential role they might serve in Internet routing. Our findings show that most HSPs are accidental (internal) route leaks, or infrastructure peering subnets, and BGP blackholing. Next, we examine the origin AS for IP prefixes announced via BGP to the Internet. Using single-origin AS for a prefix is recommended; however, the routing ecosystem of the Internet exhibits several thousand prefixes having Multi Origin AS (MOAS) prefixes. We analyze MOAS prefixes, using over six years of daily BGP Routing Information Base (RIB) snapshots from route collectors to examine the lifespan, propagation pattern, and potential relationship between the origin ASes of MOAS prefixes and the reason for MOAS prefixes’ existence on the Internet. Our findings reveal that company mergers are the largest contributors to MOAS prefixes, and examining their CIDR sizes indicates their potential for fine-grained traffic engineering. Hypergiants, including Google and Amazon, are also among the users of MOAS prefixes. Then, we analyze the relationship between IPv4 and IPv6 address families at the prefix level. We use DNS records hosted on IPv4 and IPv6 prefixes and apply the Jaccard similarity index to identify pairs of IPv4 and IPv6 prefixes having a similar set of DNS records on their IPs and refer to them as sibling prefix pairs. We identify 76k IPv4-IPv6 sibling pairs, and 60% of the sibling prefixes are registered in the RPKI. Finally, we examine the current ROA structure across five RIRs’ RPKI trees for single prefix per ROA recommendation and analyze the RPKI validation delay by setting a testbed. We find that the current ROA structure across five RIRs is not the same, and the network delay and cryptographic verification of ROAs are the main delay contributors in the RPKI synchronization process.

A copy is held

pdf, 3.0 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereimport via bibtex
Added2026-08-21 00:00 UTC
Approved bya person 2026-08-21 19:08 UTC

Filed under

routing-attacks

Cite it as

@phdthesis{sediqi2025unexpected,
  title        = {Unexpected Routes: BGP Prefixes Beyond Recommended Practices},
  author       = {Khwaja Zubair Sediqi},
  year         = {2025},
  school       = {Saarland University},
}

This record lives at https://refs.drheap.org/sediqi2025unexpected/ and will keep doing so.