Cloudflare finds 70% of BGP paths manipulated to boost provider revenue
Cloudflare research indicates that 70% of BGP paths involve the manipulation of the ORIGIN attribute, a practice often used by transit providers to prioritize traffic routes and increase revenue. The report suggests that since such manipulation undermines routing fairness and lacks technical necessity, the industry and the IETF should move toward deprecating or standardizing the attribute to 'IGP'.
Key Takeaways
- Approximately 26% of the top 50 Autonomous Systems (ASes) currently manipulate the ORIGIN attribute to attract more traffic
- Switching the ORIGIN value to 'IGP' increased path acquisition for rewriters by 18% in IPv4 and 40% in IPv6
- Six out of 16 Tier-1 networks were identified as ORIGIN rewriters, reflecting a revenue-driven 'arms race' in routing
- Cloudflare and BGP contributors are calling for the IETF to deprecate the attribute or standardize it to a universal 'IGP' value
Why It Matters
For streaming providers, this levels a technical blow to the assumption of BGP path neutrality. If transit providers are systematically rewriting attributes to siphon traffic, CDNs and origin servers may face sub-optimal latency or higher transit costs as traffic follows revenue-optimized rather than performance-optimized paths. This highlights a growing fragmentation in global routing where the largest players use policy manipulation to consolidate their traffic share. Watching whether the IETF adopts the 'Scrubbing BGP ORIGIN' draft will be critical for network engineers managing global delivery footprints.
Additional Context
The manipulation of BGP attributes is part of a broader industry struggle to secure and modernize the internet's core routing protocol. Per Reuters in June 2024, the White House and federal agencies have increasingly pressured internet service providers to adopt Resource Public Key Infrastructure (RPKI) to prevent BGP hijacking, which cost billions in lost productivity and security breaches annually. While RPKI focuses on ownership verification, the Cloudflare report highlights that even 'valid' routes are being gamed for financial gain. BGP's age—designed decades ago without modern security or fairness triggers—continues to create friction for high-scale hyperscalers who require predictable traffic flows. In related developments, the IETF has been actively debating the 'BGP-AS0' and other path validation standards to mitigate routing leaks. Data from ThousandEyes in early 2024 noted that major cloud outages are frequently traced back to misconfigured BGP filters, which are exacerbated when transit providers use non-standard attribute modifications like those found by Cloudflare. Furthermore, per a May 2024 report from Analysys Mason, the 'flattening' of the internet—where content providers peer directly with eyeballs—is reducing the influence of Tier-1 transit providers, potentially explaining why those remaining transit firms are resorting to ORIGIN manipulation to protect dwindling traffic margins. Regulators are also stepping in. In May 2024, the FCC proposed new reporting requirements for BGP security, citing the risk that manipulated or hijacked routes pose to national security and commercial stability. While the FCC's primary concern remains state-sponsored hijacking, the technical overlap between malicious hijacking and 'revenue-driven' attribute manipulation is narrow. The industry is currently split; according to a June 2024 NANOG survey, while engineers favor technical fixes, many large transit providers resist changes that would limit their ability to manage traffic according to proprietary commercial agreements.
Read full article at blog.cloudflare.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source