Researchers say U.S. Internet traffic was re-routed through Belarus
washingtonpost.com
washingtonpost.com
BGP is a great playground for injection research. The best part is via looking glass sites it's very trivial to target specific, and core, platforms.
That being said... Regardless of BGP itself beyond certificate validation and pinning we should also be doing path checking. I mentioned this to Moxie for a potential addition into Convergence, and from the page:
"Convergence trust notaries use network perspective to validate your communication by default, but can be extended to use whatever methods the notary operator would like. This might include DNSSEC, BGP data, "SSL observatory" results, or even CA validation."
...AS path should be looked at more closely in all secure communications we're delivering. It's trivial to get the AS path for the hops and, since it is generally static from known origination networks it would be relatively easy to build history of known AS path order and vet with regionalized crowd-sourcing.
Huge path swings should be obvious, today they're not to most. Some good resources are: * Team Cymru - https://www.team-cymru.org/Monitoring/BGP/ * Colorado State BGPmon - http://bgpmon.netsec.colostate.edu/ * Cyclops (UCLA) - http://cyclops.cs.ucla.edu
...and there's also BGPMon (the service), but it has turned into a more paid for service (although you can monitor 5 x AS for free). * BGPmon - http://www.bgpmon.net/
Also the author shouldn't rule out Halon's razor[1]. Advertising the wrong AS is often caused by incompetence or mistakes of network engineers. Note that I'm not a network engineer (I'm a linux monkey by trade), but know you can do BGP AS path filtering[2] ala ACLs to prevent a rogue/incompetent entity from advertising routes that dont' belong to them. If more ISPs would simply lock down their routing infrastructure a bit more, a lot of these types of attacks would be rendered mostly void.
[1] http://en.wikipedia.org/wiki/Hanlon's_razor
[2] https://ftp.apnic.net/meetings/22/docs/tut-routing-pres-bgp-...
it is entertaining to see this done in the wild.
If you can announce a relatively concise prefix of traffic you know you want and nobody notices it's pretty easy for this to go unnoticed for a period of time. As the prefix gets smaller that's harder to control however (since more specific routes will generally be installed in the routing table over less specific).
That being said it shouldn't be trivial to announce networks you don't own. This is where the people process oft breaks down.