HomeGlossaryBGP Hijacking

BGP Hijacking

Also known as: BGP hijack, route hijacking, prefix hijacking

When a network announces IP prefixes it is not authorized to originate, redirecting or intercepting traffic - accidentally or maliciously.

A BGP hijack is an announcement of address space by an ASN that has no right to originate it. Because BGP trusts announcements by default, the bogus route can spread and pull traffic toward the hijacker, causing outages, interception, or spam campaigns.

Hijacks show up as MOAS conflicts (the prefix suddenly has a second origin) or as unauthorized more-specifics. RPKI Route Origin Validation stops the common origin-based cases by making such routes RPKI-invalid; ASPA and path validation address more sophisticated path attacks.