DASH sees a large route leak in Singapore
Listen now
Description
In june of this year, the Dashboard for AS Health or DASH, a service operated by APNIC saw a leak of approximately 260,000 BGP routes from a vantage point in Singapore, and sent alerts to around 90 subscribers to our routing mis-alignment notification service which is part of DASH.BGP is the state of announcements made and heard worldwide, calculated by every BGP speaker for themselves and although its globally connected and represents “the same” network, not everyone sees all things, as a result of filtering and configuration differences around the globe. BGP also should align with two external information systems, the older Internet Routing Registry (IRR) system which uses a notation called RPSL to represent routing policy data, including the “route” object, and Resource Public Key Infrastructure or RPKI, which represents the origin-AS (in BGP, who originates a given prefix) in a cryptographically signed objected called a ROA. The BGP prefix and origin (the route) should align with whats in an IRR route object and an RPKI ROA, but sometimes these disagree. Thats what DASH is designed to do: tell you when these three information sources fall out of alignment.I discussed this incident, and the APNIC Information Product family (DASH, a collaboration with RIPE NCC called NetOX, and the delegation statistics portal called REX) with Rafael Cintra (https://blog.apnic.net/author/rafaelcintra/), the product manager of these systems, and with Dave Phelan (https://blog.apnic.net/author/dave-phelan/) who works in the APNIC Academy and has a background in Network Routing Operations.You can find the APNIC Information products here: (note that the DASH service needs a MyAPNIC login to be used)* https://dash.apnic.net (https://dash.apnic.net/) the DASH portal login page (MyAPNIC resource login needed)* https://netox.apnic.net (https://netox.apnic.net/) NetOX the Network Observatory web service* https://rex.apnic.net (https://rex.apnic.net/) Resource Explorer: delegation statistics for the worldAnd you can read about the Information Products family in these blog articles:* New Alert Options for DASH (https://blog.apnic.net/2022/12/09/new-alert-options-for-dash/)* Routing Status added to DASH (https://blog.apnic.net/2022/06/27/routing-status-added-to-dash/)* Suspicious Traffic Alerts added to DASH (https://blog.apnic.net/2022/06/02/suspicious-traffic-alerts-released-to-dash/)* Using DASH to rank economies by suspicious traffic (https://blog.apnic.net/2021/04/09/using-dash-to-rank-economies-by-malicious-traffic/)* How DASH helps monitor Network Health (https://blog.apnic.net/2020/09/09/how-dash-helps-monitor-network-health/)* Worldwide REX (https://blog.apnic.net/2023/08/07/worldwide-rex/)* Introducing REX a new approach for the internet directory (https://blog.apnic.net/2021/10/08/introducing-rex-a-new-approach-for-the-internet-directory/)* Hands-On with APNIC’s NetOX (https://blog.apnic.net/2020/09/07/hands-on-with-apnics-netox/)
More Episodes
This time on PING Doug Madory (https://blog.apnic.net/author/doug-madory/) from Kentik (https://www.kentik.com/company/) discusses his recent measurements of the RPKI system worldwide, and it's visible impact on the stability and security of BGP.Doug makes significant use of the Oregon RouteViews...
Published 05/15/24
Published 05/15/24
In this episode of PING, APNIC’s Chief Scientist Geoff Huston (https://blog.apnic.net/author/Geoff-Huston/) discusses Starlink again, and the ability of modern TCP flow control algorithms to cope with the highly variant loss and delay seen over this satellite network. Geoff has been doing more...
Published 05/01/24