How to Avoid Another Major IP Hijacking update from February 2008

YouTube isn't the first site to have its IP space hijacked. Some history, and a look at existing preventive measures.

Data Center Knowledge

February 25, 2008

2 Min Read
ITPro Today logo in a gray background | ITPro Today

The YouTube IP hijacking yesterday is not the first time that errant Internet routing assignments have caused outages. Martin Brown at Renesys notes a 2004 incident involving Turkish ISP TTNet and a 2006 event involving Con Edison. In the 2004 event TTNet "pretended to be the entire Internet" on Christmas Eve, while Con Ed assumed routes belonging to New York ISP Panix.

YouTube said it was "working with others in the Internet community to prevent this from happening again." But Renesys noted that "this story is almost as old as BGP" (the Border Gateway Protocol), which relies on trust between providers. "Our trusting routers are the BIGGEST security hole," writes Richard Stiennon at Threat Chaos. "Malicious attackers can easily disrupt the entire Internet by betraying that trust."

There was similar discussion on the North American Network Operators Group (NANOG). "Whether accidental or not, the black-holing of Youtube by Pakistan Telecom demonstrates a serious weakness in the 'longest prefix wins' rule: there is no concept of trust contained in it," Tomas Byrnes wrote on the NANOG list. "Trust, whether implicit or explicit, is inherent in all human interactions, yet expressing it in cyberspace has continued to be troublesome. In routing decisions, once you are beyond a connected (either directly or multi-hop) peer, it becomes much more difficult."


Trusted routing appears to be here to stay. "BGP is fundamental to provider relationships and will not be going away anytime soon," writes Renesys' Brown. "Cryptographic extensions to BGP have been suggested (but) these may be too taxing for router CPUs."

So what practical steps are available to reduce the likelihood of future hijackings? Both Renesys and NANOG members highlighted services that monitor changes in IP assignments and provide alerts. These services include the Internet Alert Registry, the Prefix Hijack Alert System and RIPE's MyASN service, as well as paid services like Renesys Routing Intelligence.

Ars Technica offered another possible response:

A likely result of this incident is that more network operators will start to announce their IP address blocks as a collection of /24 blocks. /24 is the smallest address range that is widely accepted between ISPs, so announcing the /24 yourself provides some protection against others doing the same. However, the problem with that is that it increases the routing tables in routers, which exacerbates problems from global routing table growth that already exist.

Read more about:

Data Center Knowledge

About the Author

Data Center Knowledge

Data Center Knowledge, a sister site to ITPro Today, is a leading online source of daily news and analysis about the data center industry. Areas of coverage include power and cooling technology, processor and server architecture, networks, storage, the colocation industry, data center company stocks, cloud, the modern hyper-scale data center space, edge computing, infrastructure for machine learning, and virtual and augmented reality. Each month, hundreds of thousands of data center professionals (C-level, business, IT and facilities decision-makers) turn to DCK to help them develop data center strategies and/or design, build and manage world-class data centers. These buyers and decision-makers rely on DCK as a trusted source of breaking news and expertise on these specialized facilities.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like