BGP Prefix Origin Validation
RFC 6811, “BGP Prefix Origin Validation”, is a Proposed Standard document published in January 2013 by P. Mohapatra, J. Scudder, D. Ward, R. Bush, R. Austein. It has since been updated by RFC 8481, RFC 8893. The canonical text is published by the RFC Editor.
Abstract
To help reduce well-known threats against BGP including prefix mis- announcing and monkey-in-the-middle attacks, one of the security requirements is the ability to validate the origination Autonomous System (AS) of BGP routes. More specifically, one needs to validate that the AS number claiming to originate an address prefix (as derived from the AS_PATH attribute of the BGP route) is in fact authorized by the prefix holder to do so. This document describes a simple validation mechanism to partially satisfy this requirement. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6811 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6810 The Resource Public Key Infrastructure to Router Protocol
- RFC 6812 Cisco Service-Level Assurance Protocol
- RFC 6818 Updates to the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List Profile
- RFC 6819 OAuth 2.0 Threat Model and Security Considerations
- RFC 6820 Address Resolution Problems in Large Data Center Networks
- RFC 6824 TCP Extensions for Multipath Operation with Multiple Addresses
- RFC 6825 Traffic Engineering Database Management Information Base in Support of MPLS-TE/GMPLS
- RFC 6826 Multipoint LDP In-Band Signaling for Point-to-Multipoint and Multipoint-to-Multipoint Label Switched Paths