Lessons
Open any lesson. Your next lesson is highlighted.
- 01 Making BGP harder to abuse
No lesson in this chapter matches that.
- Threat model: hijacks, leaks, session attacks, resource exhaustion
- Session protection: MD5, TCP-AO, GTSM, ACLs, CoPP
- maximum-prefix as a blast-radius control
- Edge prefix filtering as a security control, not just policy
- RPKI, ROAs, and origin validation states
- Acting on invalid, valid, and not-found
- Route leaks and BGP Roles / OTC
- Remotely Triggered Black Hole, destination and source based
- uRPF
- Bogon filtering and IRR-based prefix filters