IETF engineers debate BGP ORIGIN manipulation to secure streaming traffic paths
At IETF 126, engineers reviewed challenges regarding BGP protocol security, focusing on the manipulation of the ORIGIN attribute for traffic engineering. The session included discussions on the status and partial deployment challenges of validation frameworks such as ASPA, ASRAs, and the emerging DNS-based PAVA protocol.
Key Takeaways
- AS prepending currently affects 601,814 routes out of 2.2 million active paths monitored by RouteViews.
- BGP ORIGIN attributes are being rewritten to EGP to influence path selection, despite EGP being an obsolete protocol.
- ASPA deployment remains limited to open-source BGP daemons, with total RPKI objects currently in the low thousands.
- The emerging PAVA protocol proposes using DNSSEC to validate AS paths, potentially reducing RPKI synchronization overhead.
- The IETF SIDROPS Working Group has iterated on the ASPA specification 27 times over a ten-year period without an RFC.
Why It Matters
Manipulating BGP attributes allows providers to override standard path selection, potentially siphoning traffic and affecting streaming delivery performance. For CDN operators and video streamers, these vulnerabilities mean that traffic can be diverted based on economic incentives rather than network efficiency. While ASPA and PAVA offer cryptographic validation of paths, the lack of a stable RFC and the complexity of partial deployment leave BGP vulnerable to route leaks. B2B stakeholders should monitor the transition from RPKI origin validation to full path validation to ensure long-term delivery stability.
Additional Context
The debate at IETF 126 follows significant industry pressure to modernize routing security. Per Cloudflare, February 2026, the company launched new tracking tools within Cloudflare Radar to monitor the global deployment of Autonomous System Provider Authorization (ASPA). This initiative aimed to address 'route leaks'—incidents where traffic is misdirected due to configuration errors—which Cloudflare noted were critical in resolving a major January 2026 BGP anomaly in Venezuela that affected regional connectivity.
Despite technical momentum, deployment remains fragmented. Per a July 2026 update from ISBGPsafeYet, Tier-1 transit providers like Sparkle (AS6762) have recently begun actively rejecting RPKI-invalid prefixes, joining other major players like Google and Bell Canada. However, origin validation alone does not secure the entire path; AWS reported in late 2025 that it is combining RPKI with additional security checks to mitigate path-based hijacks that origin validation cannot detect.
Simultaneously, NIST has accelerated the availability of testing resources for these emerging standards. Per NIST, August 2025, the agency released the BGP RPKI IO (BRIO) open-source tool to facilitate synthetic traffic testing for ASPA and other route leak mitigation protocols. This move was intended to reduce the 'complexity drag' cited by IETF engineers, providing a standardized environment for vendors like Huawei and Juniper to validate router implementations before formal RFC finalization.
Read full article at blog.apnic.net
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source