Border Gateway Protocol (BGP)
The routing protocol that exchanges reachability between the internet's autonomous systems; announcements a peer does not filter or validate can carry false routes that redirect traffic.
The Border Gateway Protocol, version 4, defined in RFC 4271, is the routing protocol that connects the internet’s autonomous systems, the separately administered networks that make it up. Each autonomous system announces to its neighbours the address prefixes it can reach, and routers choose between paths by policy as well as by path length. BGP sessions run over TCP, on the well-known port 179.
BGP sits at the network edge, where peering relationships are set up, and its security problem is trust. The routes a peer announces are accepted as input unless they are filtered or validated, so a false announcement, whether a mistake or an attack, can redirect traffic for address space the announcer does not hold. That is route hijacking, and a related error, the route leak, passes routes on to networks that should never have received them. The controls are prefix filtering at each peering, Resource Public Key Infrastructure (RPKI) route origin validation, which checks that an autonomous system is authorised to originate a prefix, and protection of the sessions themselves.
Exam relevance: a scenario is likely to describe traffic for an organisation’s addresses suddenly flowing through an unrelated network. Candidates are expected to recognise a routing announcement problem at the edge, and to name route filtering and origin validation as the controls.