BGP Flashcards
What defines an Autonomous System (AS)?
A collection of IP prefixes under a single administrative entity with a common routing policy.
Name types of BGP routing attacks.
Blackholing, redirection, instability, prefix hijacking.
What is prefix hijacking?
Announcing unauthorized prefixes to redirect or drop traffic.
What causes BGP security issues?
Lack of authentication, misconfigurations, and susceptibility to eavesdropping and manipulation.
How can BGP threats be mitigated?
Neighbor authentication, TTL checks, prefix restrictions, and access control lists (ACLs).
What is Secure BGP (S-BGP)?
A system where nodes sign announcements to authenticate paths.
How does BGPSec enhance BGP security?
By digitally signing AS path updates and leveraging RPKI for origin validation.
What is Resource Public Key Infrastructure (RPKI)?
A PKI mapping AS numbers and IP prefixes to public keys for secure announcements.
What is a DoS attack? (Denial of Service)
Overwhelming a victim with traffic to deny legitimate access.
How can spoofing be prevented?
Using BCP 38, ingress filtering, source address validation, and IP traceback.
What is the Mirai botnet?
Malware that infects vulnerable IoT devices, turning them into a network used to launch large-scale distributed denial-of-service (DDoS) attacks, often exploiting weak passwords and outdated firmware.
What are IP traceback methods?
Logging, input debugging, controlled flooding, and marking.