BGP Vortex: Update Message Floods Can Create Internet Instabilities

The work

AuthorsFelix Stöger; Henry Birge-Lee; Giacomo Giuliari; Jordi Subira-Nieto; Adrian Perrig
Editors
Typeinproceedings
Year2025
Citekeystoger2025vortex

Where it appeared

Published in34th USENIX Security Symposium (USENIX Security 25)
PublisherUSENIX Association
Pages3613--3629

Identifiers

ISBN978-1-939133-52-6

Abstract

The Border Gateway Protocol (BGP), while essential for Internet connectivity, faces many stability and convergence challenges in today’s evolving routing ecosystem. In this paper, we present the discovery of the BGP Vortex, a configuration where just three legitimate BGP UPDATE messages can trigger persistent instability. We demonstrate that this vulnerability can be weaponized as an attack vector, potentially causing widespread Internet connectivity issues through router overload and forwarding loops. Crucially, a BGP Vortex cannot be prevented by existing security mechanisms such as BGPSEC or RPKI, because the protocol messages involved are legitimate. All major router implementations we could experiment with are susceptible to this threat. At its root, the BGP Vortex is caused by standards-compliant BGP extensions—BGP Communities in this case— that allow the modification of route preferences for traffic engineering purposes. Therefore, to aid the mitigation of this attack as well as its potential future variations, we propose a framework to determine which BGP extensions are problematic, and which are safe to deploy. Our findings highlight the need to carefully balance network operators’ traffic engineering capabilities with routing stability requirements.

A copy is held

pdf, 1.6 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereimport via bibtex
Added2026-08-04 00:00 UTC
Approved bya person 2026-08-17 11:36 UTC

Cite it as

@inproceedings{stoger2025vortex,
  title        = {BGP Vortex: Update Message Floods Can Create Internet Instabilities},
  author       = {Felix Stöger and Henry Birge-Lee and Giacomo Giuliari and Jordi Subira-Nieto and Adrian Perrig},
  year         = {2025},
  booktitle    = {34th USENIX Security Symposium (USENIX Security 25)},
  publisher    = {USENIX Association},
  pages        = {3613--3629},
  isbn         = {978-1-939133-52-6},
}

This record lives at https://refs.drheap.org/stoger2025vortex/ and will keep doing so.