FINDING · EVALUATION

In the August 2012 Bell-Dery BGP route leak, TTL analysis at per-prefix granularity revealed that two IP addresses within AS577 maintained constant TTLs and unaffected packet rates throughout the disruption, while 37 of 38 other active /16 prefixes experienced significant volume drops and TTL changes indicating rerouting through longer paths. This demonstrates that BGP route leaks can affect subnets within a single AS asymmetrically, and that TTL inspection can identify unaffected sub-AS paths.

From 2013-benson-gainingGaining Insight into AS-level Outages through Analysis of Internet Background Radiation · §IV-B · 2013 · Traffic Monitoring and Analysis

Implications

Tags

censors
generic
techniques
bgp-hijackmeasurement-platform

Extracted by claude-sonnet-4-6 — review before relying.