nanog mailing list archives

Re: ASN "Hijacked"


From: Bryton Herdes via NANOG <nanog () lists nanog org>
Date: Fri, 11 Sep 2026 15:05:53 -0500

b) resolve AS-SET into an ASN tree

c) prune from the tree ASPA violating branches

I've discussed this with a few people with the same ideas, and I can think
of few reasons not to ship it as long as it's done right.

It is appealing to get some value from the ASPAs as early as possible, and
pruning bad members from an expanded AS-SET tree could offer that.

--
Bryton Herdes
Principal Network Engineer
AS13335 - Cloudflare


On Fri, Sep 11, 2026 at 11:58 AM Saku Ytti via NANOG <nanog () lists nanog org>
wrote:

On Fri, 11 Sept 2026 at 18:04, Christopher Hawker via NANOG
<nanog () lists nanog org> wrote:

I would look at creating ASPAs objects with $rir in the first instance.
Would help combat these sorts of issues :)
Ask your upstream to create objects, then ask them to ask their
upstreams, and so on… You get the picture.

If someone feels like vibing, may I suggest.

a) recover AS-SET <-> ASN relation
    - look at RIR data, check if (mp-)export has exactly one AS-SET ->
match
    - look at peeringDB

b) resolve AS-SET into an ASN tree

c) prune from the tree ASPA violating branches

d) return prefix-list, and origin ASN list


This way anyone already doing RIR prefix-list generation, without any
ASPA support in NOS, could get a significant amount of ASPA benefits
without changing anything in the NOS side, just changing command they
call to translate customer AS-SET into prefix-list or AS origin list
or both.

--
  ++ytti
_______________________________________________
NANOG mailing list

https://lists.nanog.org/archives/list/nanog () lists nanog org/message/UOBGN4KMIREKINGTIAQ4K2ZKC62FPOUE/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/2FQHH6LNCO3QKUUBBWT6RA77OXJOKNYN/

Current thread: