AS, standing for Autonomous System, is like an ISP's name. BGP spreads routing information by rumor. For example, I start the rumor that I can route to IP addresses in 1.2.3.0/24, and tell my peer ISPs. They tell their peers I told them... etc. To prevent rumors from going in circles, you keep a record of every ISP in the path of spreading the rumor, and call it the AS path. (Otherwise you could never retract the rumor, as it would go in circles. BGP speakers do not accept rumors that they themselves are in the path of. (Except in cases of dirty hacks, but then only a finite number of times.))
This article describes fraudulent AS paths attached to (as I understood it) IP ranges that were legitimately owned by the people advertising them to Hurricane Electric. This is like you telling Hurricane Electric that I (the North Korean ISP) told you that I can route to 1.2.3.0/24, an IP address range you own, even though I told you no such thing and we are not even peers.
__=$(exec sed -n '/^4.31.198.44 /!d;=;q' /etc/hosts);
test ${#__} -gt 0||
echo 4.31.198.44 www.ietf.org >> /etc/hosts
http://www.ietf.org/rfc/rfc2650.txtAvast, NFOrce, etc. can update their BGP routing information with a routing registry probably by just sending an email with some authentication details. Apparently the veracity of provided information is not checked. The information then gets propagated to a shared routing registry database offered to the public for free by a handful of registries via WHOIS.
The blog author suggests that the inaccuracies in Maxmind may originate from fake information in WHOIS.
http://www.eecs.qmul.ac.uk/~steve/papers/geolocation-ccr-11....
This paper discusses accuracy of GeoIP databases. It concludes they are between 96-98% accurate at the country-level. Maybe the database compilers would use delay measurement for the 2-4% if the inaccuracies follow some pattern, e.g. they are consitently associated with particular countries. Maybe they already use this method. I don't know.
The IP addresses in the blog, and the idea of fake VPN exit nodes, were discussed previously: http://blog.trendmicro.com/trendlabs-security-intelligence/a...