A BGP Vulnerability on Supporting 4-Octet AS Number Space
Yang Yi-xian · Beijing Youdian Xueyuan xuebao · 2011
A new border gateway protocol(BGP) security problem,multi-exit-discriminator(MED) vulnerability,has been discovered,which could be abused in data hijacking.For the reason that BGP devices may not operate as expected with the extension of 4-octet autonomous system(AS) number,data streams could be diverted to other Internet service providers unconsciously and bring serious threat to the global network.In addition the weakness is simulated under the environment of Cisco routers,and a kind of man-in-the-middle data hijack based on the MED flaw is implemented and verified through the experiment.