研究人员发现,互联网核心路由协议中的BGP ORIGIN属性遭到大规模篡改。约70%的观测路径中ORIGIN值与源自治系统设置的值不同 [1]。
大型互联网服务商通过将ORIGIN属性篡改为IGP来吸引更多流量 [1]。在全球前50大自治系统(AS)中,26%都在进行此操作;前100大AS中,该比例为20% [1]。在6个Tier-1 AS中,16个出现了操纵ORIGIN为IGP的行为 [1]。
通过这一技术手段,操纵者获得了显著优势。在IPv4中,ORIGIN改写者额外获得了12条路由路径,增幅达18%;在IPv6中则增加33条路径,增幅达40% [1]。
研究覆盖了352个IPv4直接对等AS和315个IPv6直接对等AS [1]。现有BGP路由配置中,89.8%将ORIGIN设置为IGP,3.5%为EGP,6.7%为INCOMPLETE [1]。
根据RFC4271标准,ORIGIN属性的值"不应被任何其他发言人更改" [1]。研究人员建议废弃ORIGIN属性,以防止这类不公平的路由操纵行为 [1]。
Researchers have uncovered widespread manipulation of the ORIGIN attribute in BGP (Border Gateway Protocol), revealing that approximately 70% of observed routing paths contain ORIGIN values that differ from those set by the originating autonomous system [1]. The findings highlight a systemic problem where major internet service providers deliberately alter this critical routing parameter to redirect traffic in their favor.
Large internet carriers are systematically changing the ORIGIN attribute to IGP (Interior Gateway Protocol) to attract additional traffic [1]. Among the world's top 50 autonomous systems, 26% engage in this practice, while 20% of the top 100 do so [1]. The manipulation yields substantial gains: in IPv4 networks, those altering ORIGIN values obtained 12 additional paths representing an 18% increase, while in IPv6 networks the gain reached 33 additional paths, a 40% increase [1].
The research examined 352 IPv4 direct peer autonomous systems and 315 IPv6 direct peer autonomous systems [1]. Current BGP routing shows that 89.8% of routes have ORIGIN set to IGP, 3.5% to EGP, and 6.7% to INCOMPLETE [1]. Notably, 16 manipulative instances of changing ORIGIN to IGP were detected across six Tier-1 autonomous systems [1].
RFC 4271, the BGP protocol standard, specifies that ORIGIN attribute values "should not be changed by any other speaker" [1]. Despite this clear specification, the practice remains widespread. Researchers have recommended deprecating the ORIGIN attribute entirely to prevent such unfair routing manipulation [1].