[nsp-sec] Why do a route hijack for 1 second?

Hank Nussbacher hank at efes.iucc.ac.il
Mon Jul 20 14:53:21 EDT 2009


On Mon, 20 Jul 2009, Smith, Donald wrote:

>> They may not be aware that someone is monitoring that
>> specific /24.  And
>> they might also figure who would see a 1 second next-hop change.
> I will concede the possibility that this is the explanation but in that case
> the "bad guy" isn't too smart because there are a lot of people watching bgp changes:)

There are so many BGP "incidents" these days, that one more for a /24 is 
just noise.  Only high profile - ie. Amazon/Google/Youtube hijacks gets 
seen - but small /24s just become Yet Another Incident to log and move 
on.

-Hank



More information about the nsp-security mailing list