US 11,909,763 B2
BGP blackhole and hijack mitigation
Jakob Heitz, Santa Clara, CA (US); and Juan Alcaide, Durham, NC (US)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Apr. 7, 2021, as Appl. No. 17/224,275.
Prior Publication US 2022/0329621 A1, Oct. 13, 2022
Int. Cl. H04L 9/40 (2022.01); H04L 45/00 (2022.01)
CPC H04L 63/1466 (2013.01) [H04L 45/22 (2013.01); H04L 63/0823 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
determining, by a victim autonomous system (AS), that a first AS is diverting traffic from the victim AS to an unintended destination;
determining, by the victim AS, that the first AS is associated with a first Border Gateway Protocol (BGP) route that includes the victim AS as a destination or as an AS along the first BGP route to the destination; and
suppressing utilization of the first BGP route in propagating data to the victim AS by sending a message to a second AS to avoid traffic being hijacked by the first AS, the message to the second AS including:
a set of one or more AS numbers to avoid using to propagate data to the victim AS, wherein the set of one or more AS numbers includes the first AS;
a timestamp;
an expiration interval;
a signature of the victim AS; and
an identifier identifying a certificate for verifying the signature.