RoutePulse — Complete BGP Analytics & Security Intelligence Platform
RoutePulse sees both — and acts with mathematical proof.
18-model ML ensemble feeding an 8-gate Conviction Engine: SPRT + Thompson Sampling + Conformal Prediction. First BGP+security platform with provable false-positive bounds. 47 MITRE ATT&CK playbooks. CAD compositional detector (90% noise reduction). QR-scannable LoA. NIS2/DORA/AI-Act dossier.
BGP hijack confirmed by traffic shift? Blackholed in <3 s. Encrypted C2 over QUIC? Flagged. DGA botnet fan-out? Contained. Multi-modal FortiGate anomaly? CAD 90% noise-cut.
18 ML models. 8-gate Conviction Engine. 5-pillar threat scoring. Conformal Prediction with provable FDR bounds. 84% false-positive reduction on production AS202032.
Watch the 7-minute narrated tour
34 production dashboards, US English audio walkthrough. BGP analytics, ML brain, threat map, NIS2/DORA/AI-Act compliance dossier — the whole platform end-to-end.
From the first suspicious flow to BGP blackhole
in under 3 seconds — fully autonomous.
NOC + SOC Unified Console
Your NOC sees a route flap. Your SOC sees a threat actor. RoutePulse sees both — and correlates them. BGP hijack + traffic shift = confirmed attack, not two separate tickets in two different tools.
AI-Powered SOC Analyst
Works 24/7 alongside your team — investigating every critical alert, correlating 39 threat feeds, and orchestrating a 18-model ML pipeline across 56+ anomaly types.
8-Gate Pipeline: Detection to Blackhole in <3s
IP validation → Infrastructure check → ASN whitelist (22 CDN) → Volume gate → ThreatClassifier (10 classes) → TOCTOU lock → Router SSH → Claude AI Arbiter. Every gate must pass. Zero collateral damage on production routers.
Built for the scale of a full Internet routing table — 1.28M+ prefixes, 870K+ hosts, 40K+ flows/min — with 180 days of instant-query retention. No sampling. No blind spots. No compromises.
Why NOC & SOC Teams Choose RoutePulse
18-Model ML Ensemble
3-tier architecture: Core (Baseline, IsoForest, Markov, K-Means, Holt-Winters, Latency, ThreatIntel, Temporal, Beaconing, GraphChange), Specialized (CarpetBomb, DnsTunnel, Reflector), Tier 1 Expansion (QUIC Anomaly, Protocol Mismatch, BGP-Traffic Correlation, DGA/FastFlux, Encrypted C2 Profiler). Self-tuning via TP/FP feedback loops with precision-based adaptive learning. 56+ anomaly detection types across 8 MITRE ATT&CK categories.
Autonomous AI SOC Analyst (ANIE)
6-layer AI engine: L1 MITRE ATT&CK enrichment, L2 autonomous investigation, L3 continuous threat hunting, L4 ML orchestration, L5 self-tuning, L6 persistent network memory. Budget-aware at $1–3/day after 4-layer digest optimization.
5-Pillar Unified Threat Score
183-point composite across Cyber Events (48pt), Behavioral (40pt), ML Ensemble (30pt), External Intelligence (40pt), and FeedIntel (25pt). 15 correlation rules auto-classify severity and trigger mitigation.
52K+ Indicators, Sub-Microsecond Lookup
39 threat feeds loaded into Bloom filter for <1μs correlation against every flow. MISP integration (4,894 events, 9.9M attributes), AbuseIPDB, Shodan, and commercial blocklists in real time.
1,300x Query Acceleration
Columnar analytics engine with 17 materialized views and 9.5x compression. TopTalkers from 17s to <1s, IP lookups from 8s to 98ms. 180 days of full retention at 3.5TB, instantly queryable.
Automated Blackhole Mitigation
RTBH (Remote Triggered Black Hole) for IPv4 (/32, /24) and IPv6 (/128) via persistent SSH to Juniper MX and Huawei NetEngine routers. BGP community 65535:666 upstream signaling to 6 transit providers (RFC 7999). AI-driven NEUTRALIZE / OBSERVE / SAFE verdicts, 8-gate safety pipeline with Claude AI Arbiter, progressive ban escalation (7d to 365d), 22-ASN cloud protection, PIN auth. Cloudflare Magic Transit on-demand DDoS protection for prefix-level defense. Alert to blackhole in <3 seconds.
📡 Keep the Lights On
Six daily NOC questions — and the page that answers each one in under 5 seconds.
Traffic Analytics + Flow Analyzer
Live sFlow/IPFIX/NetFlow parsing into ClickHouse (35 tables, 9.5× compression). 1,575 SolarWinds-sourced app signatures via DPI. Top ASNs, IXP community attribution (SwissIX, MIX-IT, MINAP), per-protocol breakdown, Wireshark-style ad-hoc filter.
BMP Loc-RIB (RFC 9069)
Ingest the router's post-policy FIB as a first-class BMP feed. ~218K prefixes live on MX204 — the routes the router actually installs, with the AS-PATH, communities and RPKI status it actually uses.
Capacity Planning & Forecast
P95 billing tracker per-provider, cost-per-Mbps comparison, CDR utilization, 6-month historical trends, what-if simulator. Capacity-threshold anomaly alerts with 60-min cooldown.
BGP-LS Topology (RFC 7752)
Link-state NLRI ingestion with 2000-entry ring buffer. Interactive d3-force graph: nodes, links and prefixes straight from the IGP. Junos / Huawei VRP / Cisco IOS-XR terminology cross-reference documented.
Peer Health + Loc-RIB Monitors
BMP session uptime badges, flap detection with history, down-since timestamps, per-peer prefix counts. Auto-emailed outreach on 3-day-down via Peering Manager — GOLINE-branded templates.
External BGP Visibility
RIPE RIS Live WebSocket across 23 global vantage points. Mismatch + hijack detection, propagation trace, Last-Seen timestamp, monitored prefix watchlist with alerts on visibility changes or withdrawals.
🛡️ Hunt, Correlate, Mitigate
Six daily SOC questions — and the answer in ML, correlation and one-click mitigation.
Unified Cybersecurity Dashboard
5-pillar host scoring (Cyber + Behavioral + ML + External + FeedIntel, 0–100), 18 ML models, 42 configurable flow rules, 39 threat feeds (52K+ IoCs). Cross-source from Wazuh SIEM + Suricata IDS + FortiGate + AbuseIPDB + Shodan + Nmap parallel.
Conviction Engine (SPRT + Thompson + Causal)
Five pillars must agree: Sequential Probability Ratio Test to 99% confidence, Thompson Sampling exploration, Causal Verification, 22 CDN/cloud ASN whitelists + 4-layer SSH protection veto, Claude AI arbiter final review. 84% fewer false-positive blackholes.
Security Events Cross-Source
Every cyber event rendered with full context: target IP + hostname + destination port/proto + application + FortiGate action (color-coded block/allow) + FortiGuard CR score + policy ID + Wazuh rule level + agent name + aggregation counters (deny/unique targets/window).
Orchestrated Mitigation: RTBH / FlowSpec / CF MT
Three tools, one engine. RTBH (SSH Juniper + Huawei, BGP 65535:666) for /32-/24 blackholes. BGP FlowSpec (RFC 8955/8956) for surgical rate-limit/redirect/drop. Cloudflare Magic Transit on-demand for volumetric scrubbing. Median 17 seconds from detect to router commit.
ML + NIST/MITRE Tier-1 Detectors
18 unsupervised ML models: 17-feature IsolationForest, K-Means auto-k, Holt-Winters, Markov path-norm, temporal embeddings, beaconing detector. Plus 5 NIST/MITRE Tier-1: QUIC C2, Protocol Mismatch (T1572 tunnels), DGA/Fast-Flux, Encrypted C2 (JA3), BGP-Traffic correlation.
ANIE — 6-Layer Autonomous AI
Claude-powered autonomous intelligence engine. Every AI decision logged with reason, playbook, confidence score. 90-day audit trail for NIS2/DORA. Pre-anonymised prompts, EU endpoint, no training retention. Local-model fallback available for full data isolation.
ISP Infrastructure Manager
Two tightly-coupled operator tools that previously lived outside RoutePulse: generating Letters of Authorization for cross-connects, and tracking patch-panel inventory across every GOLINE datacenter. Consolidated into the platform with full audit trail, PeeringDB-driven autocomplete, encrypted Equinix API integration, and email delivery.
Letter of Authorization generator
Fill a structured form, the PDF is produced server-side (A4, GOLINE-branded, legal wording, verification code in accent blue). Quick Select chips for configured DCs, manual PeeringDB autocomplete for any new facility. Requester dropdown driven by the local PeeringDB Postgres mirror (34k networks + 1.3k IXPs + 276 carriers). Address auto-fills via PeeringDB org → RIPE REST → ARIN REST → RIPEstat chain. Every LoA is persisted with full audit (who issued it, when, to whom, from what cross-connect) and the PDF blob lives in the DB so it can be redownloaded or re-sent without regenerating.
Patch-panel inventory, one per datacenter
Per-DC card with Our Equipment details (Customer / Account / IBX / Cage / Cabinet / Patch Panel / Default Port / Room / Media / Rack Location / Provisioning flags) and a full-width port status grid with per-port tooltip (customer name + install date + order number). Edit mode (admin) unlocks the ports table with Lock/Unlock toggle, per-port Status / Customer / Install Date / Media / Order Number fields, Clear Port action with a confirmation dialog, and a Set Port Count prompt that resizes the array — essential for datacenters like MIX DC Caldera which have no Colocation API and require manual port entry.
Equinix Colocation API sync
One-click “Sync with Equinix” on the Equinix ZH2 card pulls the current availability of the patch panel over OAuth2 (client credentials flow, token cached in memory with refresh 60s before expiry). Smart merge preserves the customer / install date / order number fields on occupied ports — only the Equinix-reported “available” set is trusted. Credentials live encrypted in Postgres (AES-256-GCM, keyed by ENCRYPTION_KEY) and are editable + test-able from the UI, never in .env in production.
Email delivery with NOC auto-fill
Send the generated LoA to the counterparty with one click — the To field is pre-filled by looking up the recipient’s NOC / Technical contact through the new PG mirror of PeeringDB’s POC table (23k contacts). The picker uses a combined ranker: role label + email local-part pattern, so noc@ always wins even when the PeeringDB role happens to be Maintenance. Email body is a formal cover with a 14-row cross-connect summary table plus an optional operator message block, signed by the authorized signatory from Company settings. PDF attached. Reuses the existing GOLINE-branded email template so every outbound looks consistent with the rest of RoutePulse.
PeeringDB → Postgres mirror (shared)
A complete mirror of PeeringDB’s data into 9 indexed Postgres tables (33k orgs, 5.9k facilities, 34k networks, 1.3k IXPs, 276 carriers, ~70k join rows, 23k NOC/tech POCs). Full refresh in ~8.5s via a single TRUNCATE + chunked INSERT transaction, auto every 6h (1–168h configurable). Chain-triggered from Settings → Caching after every SQLite sync. Facility autocomplete, network+IX presence, and NOC lookup served in 30–50ms from the local PG mirror — the old path hitting the PeeringDB REST API took 30–60s per facility.
Shared WHOIS AS-details cache
New structured WHOIS cache (org name, address, phone, country) per ASN with a 30-day TTL, populated lazily on demand through the fallback chain RIPE REST → ARIN REST → RIPEstat → PeeringDB /net?asn=. Shared between the ISP Manager (for LoA auto-fill) and the rest of RoutePulse (AS Explorer enrichment, host intelligence). Settings → Caching has a new “AS Organization Details (shared)” section with a Test Lookup box to force-refresh a single ASN and inspect the resolved org / address / source live.
BGP Intelligence
Go Collector Engine
16MB binary, goroutine-per-router, 34+ query types, SSE eventsRIB Search
1.28M+ prefixes, best-path, communities, RPKI badgesLooking Glass
Instant prefix lookup with longest-match, per-peer comparisonPath Analysis
AS-to-AS animated Canvas flow with IP Intelligence dashboardPeer Management
Card layout by role, RIB dump status, SNMP state, peer compareCommunity Decoder
18 transit + 8 IXP dictionaries, large community RFC 8195AS Topology Graph
interactive SVG with glow filters, CAIDA roles, depth 1-3Routing Trends
Prefix growth, AS-PATH length, unstable prefix ranking, 24h-90dPath Timeline (BGPlay)
Animated AS-PATH changes with play/pause/speed controlsAS Comparison
Side-by-side routing, security, traffic, IXP presence analysisStale Detection
Router/peer inactivity with configurable thresholdsMOAS Whitelist
Known multi-origin pairs for CDN/anycast FP suppressionFlow Analytics & Traffic
Flow Collector
sFlow v5 + IPFIX/NetFlow v9, 5 active sources, auto samplingColumnar Storage
35 tables, 17 MVs, ZSTD 9.5x compression, 180-day TTLDPI Classification
1,575 apps, 272 port rules, ~92% classification rateFlow Query Builder
Kentik-level ad-hoc queries, stacked time series, CSV exportGeoIP Heatmap
City-level MaxMind mapping, country tables, host overlayWeathermap
NOC-style SVG topology, SNMP throughput, animated dashesRIB Correlation
Real-time BGP enrichment, 4-tier LPM, 100% enrichment rateIXP Community Attribution
SwissIX/MIX-IT/MINAP community-based traffic splitSecurity & Compliance
ASPA Validation
RFC 9582 route leak detection, 4,040 provider pairsROA Lifecycle
VRP diff engine, expiry badges, optimizer suggestionsBehavioral Scoring v3
14 components, 9 parallel CH queries, max 40ptsThreat Feed Intelligence
39 feeds, Bloom filter, MISP 4,894 events, CISA AISWazuh SIEM
Suricata IDS + FortiGate IPS + cross-source correlation, 18M+ alertsProgressive Ban System
Strike escalation 7d-365d, observation window, auto-re-banBogon Detection
14 IPv4 + 9 IPv6 bogon ranges, critical severity alertsCloud ASN Protection
Google/Cloudflare/AWS/Meta never blackholed, smart gatesAbuseIPDB Integration
Confidence scoring, auto-reporting, 23 category mappingsShodan Integration
Open ports, CVE list, OS detection, cloud provider IDIXP LAN Leak Detection
2,500+ IXP LAN prefixes, DFZ leak monitoringAS Security Badges
RPKI, MANRS, ASPA posture per ASN across all viewsSuricata IDS Native
9 event types, severity-gated, noise SID filtering, MITRE enrichmentFortiGate IPS Ingestion
CEF parser, IPS/UTM alerts, crscore, FortiGuard linksNmap Attacker Scanner
Top-200 ports, OS detection, service versions, Pillar 4 scoringMITRE ATT&CK Mapping
Auto-enrichment from Suricata + Wazuh rules, tactic badges4-Tier ASN Resolution
GeoIP + Flow + RIB LPM + Peer table = 100% coverageDiscoveries Tab
Live host discovery feed with source, direction, SIEM correlationThreat Detection Expansion
ThreatClassifier (10 Classes)
Class-driven mitigation: 10 threat classes (noise, recon, behavioral, c2_suspect, c2_confirmed, tunnel, botnet, volumetric, amplification, carpet_bomb) routed to 3 defense layers. Replaces score-threshold blackholing.
Claude AI Arbiter (Gate 8)
Final safety gate: Claude Opus 4.6 asks “can the FortiGate handle this?” before any BGP blackhole. Safe-side default: AI unavailable = DENY. ~bash.30/day. Full audit trail.
8-Gate Blackhole Pipeline
IP validation → Infrastructure → ASN whitelist (22 CDN) → Volume gate → Classification → TOCTOU → Router SSH → AI Arbiter. Every gate must pass.
5 New NIST/MITRE Detectors
QUIC Anomaly (encrypted C2 on UDP/443), Protocol Mismatch (T1572 tunnel detection), BGP-Traffic Correlation (ISP-unique hijack confirmation), DGA/Fast-Flux (botnet fan-out), Encrypted C2 Profiler (JA3 + flow).
PTR Auto-Protection
DNS reverse lookup auto-protects RIPE Atlas (377+ hosts), DNS Root Servers, RIPE NCC, NLNOG RING. Toggleable from Settings GUI.
Configurable Safety Gates
Volume Gate (1MB–1GB), AI Arbiter toggle, Early Release (auto-release when threat subsides), 22 CDN/cloud ASN whitelist — all adjustable from Settings.
Observability & Platform Hardening
Native Event Loop Instrumentation
Libuv-level event loop delay histogram + CPU utilization ratio + post-major-GC heap sampling via Node.js perf_hooks, always-on at <0.1% overhead. Direct UI-freeze measurement — 11 new Prometheus gauges surface max, p50/p95/p99, utilization, and GC pauses.
On-Demand CPU Profile & Heap Snapshot
V8 inspector.Session endpoints capture .cpuprofile (5–120s) and .heapsnapshot into /tmp, downloadable via admin-gated endpoint with filename allowlist. Line-level flame graphs in Chrome DevTools or speedscope.app — no –inspect flag, no external port, runs on the live production process.
Profiler Dashboard (4 Tabs)
Settings > Profiler: Overview (4 health KPI cards with threshold colouring + SVG sparklines + GC summary + top 5 hottest spans), Spans (detailed table), Profiling Tools (CPU profile + heap snapshot buttons + captures list), Configuration. Everything an operator needs to diagnose a freeze in one page.
Cooperative Yield Helper
profiler.createYielder(thresholdMs) wrapper converts unbounded CPU bursts into bounded-latency bursts without per-call-site setImmediate plumbing. Fast-path is a single Date.now() comparison. Wired into the three heaviest ML inference loops (isolation forest, K-means, temporal embeddings).
Persistent Session Store
user_sessions PostgreSQL table (token PK + user_id FK CASCADE + denormalised username/role + indexed expires_at) hybrid-cached in memory for O(1) sync reads on every authenticated request. Operator sessions survive systemctl restart — no re-login after every deploy. 30-day TTL, hourly expiry cleanup.
PostgreSQL Buffer Pool Tuning
shared_buffers 12 GB, effective_cache_size 24 GB, work_mem 64 MB, checkpoint_timeout 15 min, max_wal_size 8 GB on a 47 GB host alongside Node + ClickHouse. Cache hit ratio steady at 99%+. The /metrics endpoint events query was rewritten from count(*) filter(where) full-scan to index-only subselects (8.4s → 1.1s).
License Server & 5-min Heartbeat
Standalone license authority with Ed25519 signing + clone-resistant hardware UID (SHA-256 of SMBIOS product UUID + machine-id + rootfs UUID + primary MAC). 5-minute heartbeat cadence so revocations propagate fast. 4 editions, admin GUI with audit log, daily SQLite backup.
Transactional Email Branding
Consistent "Powered by RoutePulse" footer with explicit https://routepulse.goline.ch link across every outbound email: peering requests, peering-down notifications, user invites, SMTP tests, AI reports, notification alerts, reminders. Outlook-compatible HTML in every flow.
Auto-Synced Prometheus Version Label
External label routepulse_version in prometheus.yml is rewritten and SIGHUP-reloaded on every release via scripts/release.js. Telegram alerts routed through Alertmanager always show the currently-running build — no more stale version drift across deployments.
BGP Advances & Operator UX
BMP Loc-RIB Live (RFC 9069)
Ingest the router’s post-policy Loc-RIB as a first-class BMP feed (PeerType=3, synthetic locrib@... peer key). MX204 live in production exposes ~218K FIB prefixes — the routes the router actually installs, not just what it receives from a peer. Dedicated "Loc-RIB Monitors" section on /peers with per-VRF breakdown and prefix count.
BGP-LS Topology (RFC 7752)
Link-state NLRI ingestion with 2000-entry ring buffer and a dedicated /topology-ls page rendering nodes, links and prefixes via d3-force. Junos, Huawei VRP and Cisco IOS-XR terminology cross-reference documented (link-state / link-state-family / traffic-engineering).
BGP FlowSpec v4/v6 (RFC 8955/8956)
Full parser for the carrier-grade mitigation protocol used to signal granular rate-limit, redirect and drop rules between ASes. Wired audit-first (log + event + /settings/flowspec review page) so operators validate every upstream rule before it takes effect; the same pipeline is the foundation for originating outbound FlowSpec mitigations to transit providers — more targeted than a /32 blackhole.
FortiGate Rich Attack Context
Every cyber_siem_fw_* event on /security-events renders a dedicated FortiGate panel: target IP (clickable), target hostname, destination port/proto, application, FortiGate action (color-coded block/allow), FortiGuard CR score & reputation level, policy ID, Wazuh rule level, agent name, plus aggregation counters (deny count, unique targets/ports, time window). Operators can tell at a glance which asset was hit and how severe FortiGuard considered it — without drilling into raw JSON.
BGP Session Startup Grace
Configurable 0–60 min grace window post-restart (default 5) that suppresses snmp_bgp_up / snmp_bgp_down / snmp_unreachable / snmp_recovered dispatches while SNMP polling converges. Internal state tracking still updates so the first post-grace poll has a correct baseline — only the notification side is gated. No more Telegram spam on every deploy.
Profiler Master Toggle (Hot-Reload)
One-click master switch on /settings/profiler turns the full span profiler on or off without a service restart. Toggling OFF also flushes the ring buffer and client-side history so the UI actually empties out; snapshot polling drops 3s→15s. Near-zero overhead fast path when disabled (single boolean branch per span call) — safe to leave dormant in production.
Europe/Zurich Timezone Everywhere
Every operator-facing timestamp renders in it-CH locale with explicit Europe/Zurich (CET/CEST). 40+ UI locations and 15+ ClickHouse billing / aggregation queries anchored locally — current-billing-month boundary flips at local midnight, not 02:00 CEST. Shared fmtCET / fmtCETDate / fmtCETTime helper prevents future drift.
AI & Machine Learning
ANIE 6-Layer Pipeline
L1 MITRE enrichment, L2 investigation, L3 threat hunting, L5 self-tuning, L6 memoryAI Analyst Chat
Claude-powered BGP investigation with 8 real-time toolsAI Threat Mitigation
7-day flow profiles, NEUTRALIZE / OBSERVE / SAFE verdictsAuto-Tune Engine v2
Scanner ASN auto-approve, stale cleanup, threshold tuningCorrelation Engine v5
15 cross-model rules incl. beacon convergence, lateral movementAI Cost Optimization
$282/day reduced to $1-3/day, 4-layer digest pipelineThreat Intel Model
3-source fusion, 0.18 ensemble weight, 52K+ indicatorsML Host Auto-Categorize
130+ infra hosts from 8 sources, 70+ role categoriesTemporal Embeddings
8-dim per-host behavioral trajectory, Mahalanobis distanceBeaconing Detector
Inter-arrival CV + Shannon entropy, catches jittered C2Graph Change Detection
Persistent edge graph, lateral movement, hub formationHijack Impact Simulator
CAIDA BFS, RPKI/ASPA resilience score 0-100, tier analysisOutage Correlation
5 signal types, 10-min window, active/recovering lifecycleBGP Digital Twin
Peer down/add/depreference what-if on live RIBAI Incident Response
5 playbooks, auto-trigger on CRITICAL, TTD/TTM/TTR SLARed Team Framework
10 attack scenarios, detection matrix, evasion resistanceConviction Engine
SPRT + Thompson Sampling + Causal Verification, 3-tierActive Learning
Uncertainty sampling, operator review prioritizationEvaluation Framework
P/R/F1 per model from ground truth, weekly + bootPrefix Watchlist
Custom prefix monitoring, origin/path/subprefix alertsHost Roles (5-tab)
Uncategorized, Classified, Discovered, Well-Known, CategoriesDark IP Detection
CAIDA ghost method, outbound <0.1% + avg packet <100BStreaming Telemetry
gNMI/gRPC ready framework, SNMP enhanced, 1s resolutionPrefix Intelligence
4-tab deep dive: Security, Traffic, Visibility, Anomalies18/18 ML Scoring
All models contribute to host threat score via AS→IP propagationImmediate Scoring
18 models on same IP → bypass 2-min timer, instant re-scoreInfrastructure & Monitoring
SNMP BGP Monitoring
SNMPv2c polling on 6 routers, FSM state tracking, MikroTik APIData Plane Probing
ICMP ping, TCP connect, HTTP GET with threshold alertingWorker Auto-Restart
Exponential backoff, circuit breaker, DB cleanup on OOMService Control Panel
Restart 5 services, CPU/RAM gauges, live log viewerRBAC User Management
Admin/Viewer roles, email invites, 24h session TTLAPI Key Management
Centralized keys: MANRS, PeeringDB, Shodan, AbuseIPDB, ClaudeCache Management
PeeringDB SQLite, CAIDA, Whois LRU, RPKI VRP pre-warmingLog Level Control
4 levels, file logging with daily rotation, 3-day retentionBackup & Restore
9-table ZIP export/import, atomic transactions, preview panelData Retention
Per-table retention config, daily auto-purge, manual triggersWebSocket Push
Socket.io server-push, eliminates 12 req/min per tabAES-256-GCM Encryption
Credential encryption at rest, ENCRYPTION_KEY env varIntegration & API
47 Notification Types
Telegram + Email + Webhook + Recipes across 8 categoriesScheduled Reports
Daily/weekly/monthly via Email, Telegram, Webhook. AI digest 06:00 UTCCompliance PDF Reports
3 templates, 12 sections, GOLINE branding, PDFKit engineREST API (7 endpoints)
/api/v1/ with rp_xxx key auth, 60 req/min rate limitPrometheus /metrics
40+ metrics: routers, peers, RPKI, flows, ML, anomalies, CPU, RAMGrafana Dashboard
28-panel template, 7 rows, downloadable JSON, setup guideMCP Server
11 tools via Streamable HTTP, Claude Desktop + Cursor supportWebhook Recipes
Slack blocks, Discord embeds, PagerDuty incidents, Jira issuesEmail Templates
GOLINE-branded HTML, Outlook / Gmail / Thunderbird compatibleLive Event Feed
Socket.io broadcast of all system events to connected clientsAS Enrichment
CAIDA, PeeringDB SQLite, RIPE Whois, GeoIP2, Team Cymru, RDAPChangelog
In-app 400+ version history with category badges and searchMore of what RoutePulse does
The headline sections above are a selection, not the whole toolkit. A curated look at the additional capabilities operators rely on day to day.
Looking Glass
Instant lookup tool: paste an IP or prefix and get every matching route from the live RIB, best path highlighted, with origin AS, AS-PATH, communities, and RPKI status. Supports both exact match and longest-match (covering prefix).
Path Analysis
Animated AS-to-AS path explorer: pick a destination, see how traffic actually flows out of your AS through transit and IXP peers, with particles flowing along each AS-PATH on a zoomable canvas.
Path Timeline (BGPlay)
BGPlay-style animated visualization of AS-PATH changes for a prefix: pick a time window (1h–7d), press play, see paths appear and disappear over time with announce/withdraw color coding, per-path tracking, speed control.
Community Decoder
Decodes BGP community values into human-readable labels using built-in dictionaries for 18 transit providers + 8 IXP route servers (e.g. `7018:1234` → AT&T action).
AS Comparison Tool
Side-by-side comparison of two AS numbers: identity cards (name, country, type), routing stats (prefixes, paths, transit relationship), security badge comparison (RPKI / MANRS / ASPA), CAIDA relationship classification, PeeringDB metadata, traffic vo
AS Topology Graph
Force-directed graph of the AS-level topology around your network: nodes are ASes, edges are paths, colored by role (transit / IXP / peering / customer). Configurable depth (1-3 hops), force vs hierarchical layout, drag/zoom/pan, touch-friendly.
BGP Sankey Diagram
Animated Sankey diagram showing how traffic flows Source AS → Your AS → Destination AS, with particles moving along each link at 60fps. Slider controls path depth, group-by toggle (origin AS / next-hop / IXP), click-to-drill detail panel.
BGP Stats History
A 5-minute snapshot loop captures the key BGP KPIs (IPv4/IPv6 prefix counts, active peer count, updates/sec, RPKI valid/invalid/unknown coverage) into a database table with 90-day retention.
BGP What-If Simulator
Interactive RIB simulation.
Outage Correlation Engine
Automatically groups 7 different signal types (mass withdrawal, peer flap, traffic drop / shift, visibility drop, probe alert, ML baseline deviation) into single outage events per AS, with a sliding 10-min correlation window.
Routing Trends
Long-term routing-table evolution charts: prefix growth (IPv4 / IPv6) over time, average AS-PATH length, unique ASN count, prefix length histograms (/8 through /24+), top unstable prefixes. Period selector 24h to 90d.
BGP-LS Topology
For MPLS-TE backbones, RoutePulse ingests the IGP topology (OSPF or IS-IS Link-State Database) through BGP-LS (RFC 7752).
RIB Explorer
Browse the full Internet routing table (~1.28M IPv4 + IPv6 prefixes) as RoutePulse sees it from your routers.
Router Forwarding-Table Visibility
See exactly which routes a router has chosen to install in its forwarding table — not just the routes received from neighbors.
Flow Query Builder
Ad-hoc query engine in the spirit of Kentik / Akvorado.
Application Classification (DPI)
1,575 application signatures cover ~92% of observed flows. Bidirectional port + protocol matching with O(1) lookup, hostname-based DNS resolution, "match any port" rules for IP-only signatures.
Peering Analytics
Identifies which transit ASes you carry traffic to that have a presence at one of your IXPs — i.e. peering candidates that would let you offload paid transit. Score formula combines absolute traffic volume with prefix breadth, sorted by best ROI.
Peering Manager
Guided email-based peering outreach. Candidates tab ranks potential peers by 24h bilateral traffic and shared IXPs, with status badges (sent / rejected / accepted).
IXP Community Attribution
Tags traffic with which IXP it crossed using BGP community values (20203:2003 = SwissIX, 20203:2004 = MIX-IT, 20203:2005 = MINAP). This catches IXP traffic that the AS-PATH alone wouldn
ClickHouse Storage Layer
All flow data lands in a 15-table ClickHouse layout: 1 raw flows table + 14 materialized views pre-aggregating the heavy queries (peer billing, IXP community attribution, ML hourly-per-AS, etc.).
Multi-Vendor Flow Collector
Receives sFlow v5 (UDP 6344) and IPFIX / NetFlow v9 (UDP 4740) from your routers — auto-detected from the packet header. Currently ingesting from MX204, NE8000, and three MikroTik CCR2004 (SwissIX, MIX-IT, MINAP).
AS Enrichment for IPFIX/NetFlow
IPFIX / NetFlow flows from MikroTik and Juniper inline-jflow often arrive without BGP AS info.
AI Analyst Chat
Conversational BGP investigator backed by Claude with 8 real-time tools: RIB lookup, anomaly search, peer status, traffic summary, RPKI status, network health, AS info, path analysis.
AI Insights
Five proactive AI-generated reports the operator doesn
Machine-Learning Detection Engine
Eighteen ML models in pure TypeScript working as an ensemble.
ML Brain Dashboard
A single ML Brain page with four focused tabs so every artifact lives where it conceptually belongs. Models tab is the System Overview (Brain Canvas, Brain Maturity, 18-Model Knowledge Grid, ML Configuration, System Vitals).
MOAS Whitelist
Whitelist of known legitimate Multi-Origin AS pairs (e.g. anycast prefixes shared by Cloudflare, Google, Akamai) so they don
MISP Integration
Connected to the GOLINE MISP instance (4,894 events, 9.9M attributes, 85 feeds). RoutePulse pulls from the MISP REST API every 15 minutes with the to_ids filter applied.
ASPA Validation
Cryptographic route-leak detection per RFC 9582 using RPKI ASPA objects. RoutePulse walks each AS-PATH hop and verifies provider authorization against ~4,040 provider pairs from rpki-client.org.
Prefix Watchlist
Watch any external prefix for origin change, AS-PATH change, or subprefix announcement. Each prefix has per-event alert toggles, an expected origin AS, live RIB status, and flows through the full notification pipeline.
IRR Cross-Validation
Automated comparison of live BGP routing state against IRR (Internet Routing Registry) route objects via the RIPE REST DB API.
Go Collector Engine
The high-performance Go binary that listens for BGP and BMP sessions from your routers.
Network Weathermap
NOC-style SVG topology of your backbone: FortiGate, MX204, NE8000, the three IXP routers. SNMP-polled interface throughput on each link, with utilization % and capacity labels.
Data Plane Probing
Active verification that your data plane is actually working, not just announced in the RIB.
Webhook Recipes
Pre-built notification recipes for popular destinations so integration with a corporate tool is a single form, not a custom script: Slack (rich message blocks), Discord (embed cards), PagerDuty (automatic incident creation with severity mapping), and
Prometheus Metrics
Over 55 Prometheus metrics exposed in text format, refreshed in the background every 10 seconds so scrapes always return in about 4 ms (previously 11-54 seconds under load).
System API Key
An admin-level API key for CLI automation and testing, auto-generated at boot and authenticated via the `x-api-key` HTTP header. Settings > Integrations exposes an eye toggle, copy button, and regenerate with confirmation.
License Server
Standalone license authority at https://license.routepulse.goline.ch issues, renews, and revokes RoutePulse licenses signed with an Ed25519 keypair.
Cloudflare Magic Transit & RTBH
☁️🛡️ Real-time DDoS Protection
Webhook endpoint receives Cloudflare alerts in real-time (5s Telegram delivery). 11 alert types: L3/L4 DDoS, MNM auto-advertisement, tunnel health, BGP hijack. Smart debounce: 10s for DDoS (consolidates multiple CF webhooks), instant for critical. CF payload parser extracts Gbps/Mpps from all alert formats. Tested with 7 Gbps / 14.5 Mpps real DDoS attacks.
📡 BGP Prefix Management
Advertise/withdraw 5 on-demand prefixes (4 IPv4 + 1 IPv6) with verify-after-write safety (GET confirms PATCH before updating state — prevents BGP blackhole on API failure). Manual advertise skips auto-withdraw. Auto-withdraw check every 15s with instant calm detection from webhooks. 5-retry API resilience (0/3/8/15/30s backoff, 60s timeout).
📋 124 DDoS L3/L4 Rules
Full searchable table of all Cloudflare managed DDoS rules. 70 service presets for custom overrides (Web, VPN, VoIP, Database, Gaming, Industrial/IoT). Simple + Advanced wirefilter editor.
🗄 Tunnels, CNI & Static Routes
GRE/IPsec tunnel + CNI monitoring with near real-time throughput (5-min window from magicTransitNetworkAnalyticsAdaptiveGroups). CNI V2 interconnect status (Equinix ZH4, 10G). DDoS intelligence dashboard: Protection Ratio (pass vs drop), Top Attack Sources (ASN + country), Mitigation Edge Locations (CF PoPs). 14 static routes with priority-based failover.
RTBH Blackhole (IPv4/IPv6)
Inject/withdraw /32, /24 (IPv4) and /128 (IPv6) via persistent SSH. BGP community 65535:666 upstream signaling.Router Route Verification
Live SSH query confirms active blackhole routes on upstream routers. Full audit trail.Auto-Withdraw Logic
15-minute calm period auto-withdraws prefixes (15s check interval). Attack-end webhook starts countdown instantly. Manual advertise skips auto-withdraw. Verify-after-write prevents state desync.Attack Statistics
Peak attack tracking, aggregate events (total Mbps/pps/sources), per-prefix history. Smart micro-mitigation filtering (<1000 pps = info, not notified). 8 redesigned Telegram templates with auto Gbps/Mpps formatting.Built for Enterprise
Bloom filter, 52K+ indicators
Automated mitigation response
Four-tier resolution chain
Materialized views, optimized storage
From $282/day to $1-3/day
Zero packet loss ingestion
400 features, 120 pages, 58 tRPC routers, 965 endpoints. Designed and built entirely in-house. High-performance binary protocol parsers, columnar analytics engine (44 ClickHouse tables — 35 base + 9 materialised views, 1.6B+ rows), real-time streaming architecture, 18-model ML ensemble with adaptive learning and CAD compositional anomaly detector (90% noise reduction on multi-modal hosts), 8-Gate Conviction Engine (SPRT + Thompson Sampling + Conformal Prediction with provable FDR bounds), 47 MITRE ATT&CK playbooks with agentic AI response (ANIE 6-layer Claude pipeline, €1–3/day spend), and native SIEM integration (Wazuh + Suricata IDS + FortiGate IPS with rich attack-context panels). AES-256-GCM encryption at rest, RBAC access control, WORM cryptographically-chained audit trail (append-only hash chain), NIS2 / DORA / AI-Act compliance dossier generator with Ed25519 signed manifests + SHA-256 hash-chained audit entries, public QR-scannable Letter of Authorization verifier.
Built for AS202032
RoutePulse is engineered and operated by the GOLINE SOC team — providing 24/7 BGP analytics, threat intelligence, and automated defense for our network infrastructure.
Visit RoutePulse