LIVE · cybersecurity feed
Live wire
security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

zeroday.news · 8d ago

A recent analysis has uncovered widespread manipulation of the BGP ORIGIN attribute by transit providers, a practice reportedly affecting a significant majority of BGP paths. The findings indicate that approximately 70% of BGP paths are subject to rewrites of their ORIGIN attribute, a modification apparently undertaken by transit providers to gain traffic advantages. This reported manipulation raises questions about the integrity of BGP route selection and its broader implications for Internet routing.

The BGP ORIGIN attribute is a well-established component of BGP path selection, intended to indicate the origin of a route within an Autonomous System (AS). It typically takes one of three values: IGP (internal to an AS), EGP (external via EGP), or INCOMPLETE (origin unknown or learned via other means). This attribute plays a role in the BGP best path selection algorithm, where a lower ORIGIN value (IGP being preferred over EGP, and EGP over INCOMPLETE) can influence a router to select a particular path. The reported rewrites suggest that transit providers are altering this attribute, presumably from a less preferred value to a more preferred one, to encourage traffic to flow through their networks.

The mechanism of this manipulation likely involves transit ASes intercepting BGP updates and modifying the ORIGIN attribute before re-advertising them to their peers or customers. For instance, a route originally marked as INCOMPLETE might be changed to IGP or EGP, making it appear more authoritative or desirable in the eyes of downstream routers applying the BGP best path selection process. This could effectively steer traffic away from paths that would otherwise be chosen based on the original, unaltered BGP attributes.

The scope of this issue appears to be substantial, with the analysis suggesting nearly 70% of BGP paths are affected. This widespread manipulation could lead to suboptimal routing decisions, as traffic might be directed through less efficient or more congested paths due to an artificially inflated ORIGIN attribute. Such practices could also complicate network troubleshooting and performance analysis, as the reported BGP attributes would not accurately reflect the true origin or characteristics of a route.

Mitigation for this class of BGP attribute manipulation is challenging, as it often occurs within the operational practices of transit providers. Network operators typically rely on the integrity of BGP attributes received from their peers. However, in cases where such manipulation is suspected, operators might employ other BGP path selection mechanisms, such as local preference, AS path length, or MED (Multi-Exit Discriminator), to exert more control over their outbound routing decisions. Filtering BGP updates based on expected ORIGIN attributes could also be considered, though this might be complex to implement at scale without inadvertently disrupting legitimate routes.

The findings underscore a broader tension in Internet routing between established protocol mechanisms and the commercial incentives of network operators. The BGP ORIGIN attribute, like other BGP attributes, relies on a degree of trust among participants in the global routing system. When this trust is undermined by deliberate manipulation for traffic advantage, it can degrade the overall efficiency and predictability of the Internet. The analysis reportedly advocates for the deprecation of the ORIGIN attribute in route selection, suggesting a re-evaluation of its role in an environment where its integrity cannot be consistently assured.

ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.