RoutePulse — Complete BGP Analytics & Security Intelligence Platform
RoutePulse sees both — and acts with mathematical proof.
18-model ML ensemble feeding an 8-gate Conviction Engine: SPRT + Thompson Sampling + Conformal Prediction. First BGP+security platform with provable false-positive bounds. 47 MITRE ATT&CK playbooks. CAD compositional detector (90% noise reduction). QR-scannable LoA. NIS2/DORA/AI-Act dossier.
BGP hijack confirmed by traffic shift? Blackholed in <3 s. Encrypted C2 over QUIC? Flagged. DGA botnet fan-out? Contained. Multi-modal FortiGate anomaly? CAD 90% noise-cut.
18 ML models. 8-gate Conviction Engine. 5-pillar threat scoring. Conformal Prediction with provable FDR bounds. 84% false-positive reduction on production AS202032.
Watch the trailer (3:48, 19 screens)
13 production screens, US English narration: the NOC first — traffic, data coherence, BGP anomalies, RPKI — then the SOC: War Room, RA-VPN siege ladder, Cloudflare Magic Transit, mitigations, identity, ML brain, and the compliance evidence.
Watch the full tour (6:54, 37 screens)
Every page of the platform, in the same order: the NOC, the SOC, then the evidence. US English narration.
From the first suspicious flow to BGP blackhole
in under 3 seconds — fully autonomous.
NOC + SOC Unified Console
Your NOC sees a route flap. Your SOC sees a threat actor. RoutePulse sees both — and correlates them. BGP hijack + traffic shift = confirmed attack, not two separate tickets in two different tools.
AI-Powered SOC Analyst
Works 24/7 alongside your team — investigating every critical alert, correlating 39 threat feeds, and orchestrating a 18-model ML pipeline across 56+ anomaly types.
8-Gate Pipeline: Detection to Blackhole in <3s
IP validation → Infrastructure check → ASN whitelist (22 CDN) → Volume gate → ThreatClassifier (10 classes) → TOCTOU lock → Router SSH → Claude AI Arbiter. Every gate must pass. Zero collateral damage on production routers.
Built for the scale of a full Internet routing table — 1.28M+ prefixes, 870K+ hosts, 40K+ flows/min — with 180 days of instant-query retention. No sampling. No blind spots. No compromises.
Why NOC & SOC Teams Choose RoutePulse
18-Model ML Ensemble
3-tier architecture: Core (Baseline, IsoForest, Markov, K-Means, Holt-Winters, Latency, ThreatIntel, Temporal, Beaconing, GraphChange), Specialized (CarpetBomb, DnsTunnel, Reflector), Tier 1 Expansion (QUIC Anomaly, Protocol Mismatch, BGP-Traffic Correlation, DGA/FastFlux, Encrypted C2 Profiler). Self-tuning via TP/FP feedback loops with precision-based adaptive learning. 56+ anomaly detection types across 8 MITRE ATT&CK categories.
Autonomous AI SOC Analyst (ANIE)
6-layer AI engine: L1 MITRE ATT&CK enrichment, L2 autonomous investigation, L3 continuous threat hunting, L4 ML orchestration, L5 self-tuning, L6 persistent network memory. Budget-aware at $1–3/day after 4-layer digest optimization.
5-Pillar Unified Threat Score
183-point composite across Cyber Events (48pt), Behavioral (40pt), ML Ensemble (30pt), External Intelligence (40pt), and FeedIntel (25pt). 15 correlation rules auto-classify severity and trigger mitigation.
52K+ Indicators, Sub-Microsecond Lookup
39 threat feeds loaded into Bloom filter for <1μs correlation against every flow. MISP integration (4,894 events, 9.9M attributes), AbuseIPDB, Shodan, and commercial blocklists in real time.
1,300x Query Acceleration
Columnar analytics engine with 17 materialized views and 9.5x compression. TopTalkers from 17s to <1s, IP lookups from 8s to 98ms. 180 days of full retention at 3.5TB, instantly queryable.
Automated Blackhole Mitigation
RTBH (Remote Triggered Black Hole) for IPv4 (/32, /24) and IPv6 (/128) via persistent SSH to Juniper MX and Huawei NetEngine routers. BGP community 65535:666 upstream signaling to 6 transit providers (RFC 7999). AI-driven NEUTRALIZE / OBSERVE / SAFE verdicts, 8-gate safety pipeline with Claude AI Arbiter, progressive ban escalation (7d to 365d), 22-ASN cloud protection, PIN auth. Cloudflare Magic Transit on-demand DDoS protection for prefix-level defense. Alert to blackhole in <3 seconds.
📡 Keep the Lights On
Six daily NOC questions — and the page that answers each one in under 5 seconds.
Traffic Analytics + Flow Analyzer
Live sFlow/IPFIX/NetFlow parsing into ClickHouse (35 tables, 9.5× compression). 1,575 SolarWinds-sourced app signatures via DPI. Top ASNs, IXP community attribution (SwissIX, MIX-IT, MINAP), per-protocol breakdown, Wireshark-style ad-hoc filter.
BMP Loc-RIB (RFC 9069)
Ingest the router's post-policy FIB as a first-class BMP feed. ~218K prefixes live on MX204 — the routes the router actually installs, with the AS-PATH, communities and RPKI status it actually uses.
Capacity Planning & Forecast
P95 billing tracker per-provider, cost-per-Mbps comparison, CDR utilization, 6-month historical trends, what-if simulator. New: least-squares saturation forecast (days-to-80%/95% with confidence badges) and commit-burn projection with month-end overage in CHF, plus a dashboard Capacity Runway KPI.
BGP-LS Topology (RFC 7752)
Link-state NLRI ingestion with 2000-entry ring buffer. Interactive d3-force graph: nodes, links and prefixes straight from the IGP. Junos / Huawei VRP / Cisco IOS-XR terminology cross-reference documented.
Peer Health + Loc-RIB Monitors
BMP session uptime badges, flap detection with history, down-since timestamps, per-peer prefix counts. Auto-emailed outreach on 3-day-down via Peering Manager — GOLINE-branded templates.
External BGP Visibility
RIPE RIS Live WebSocket across 23 global vantage points. Mismatch + hijack detection, propagation trace, Last-Seen timestamp, monitored prefix watchlist with alerts on visibility changes or withdrawals.
🛡️ Hunt, Correlate, Mitigate
Six daily SOC questions — and the answer in ML, correlation and one-click mitigation.
Unified Cybersecurity Dashboard
5-pillar host scoring (Cyber + Behavioral + ML + External + FeedIntel, 0–100), 18 ML models, 42 configurable flow rules, 39 threat feeds (52K+ IoCs). Cross-source from Wazuh SIEM + Suricata IDS + FortiGate + AbuseIPDB + Shodan + Nmap parallel. Now with an interactive 24h attack heatmap (per-hour drill-down) and a live threat ticker streaming the latest events.
Conviction Engine (SPRT + Thompson + Causal)
Five pillars must agree: Sequential Probability Ratio Test to 99% confidence, Thompson Sampling exploration, Causal Verification, 22 CDN/cloud ASN whitelists + 4-layer SSH protection veto, Claude AI arbiter final review. 84% fewer false-positive blackholes.
Security Events Cross-Source
Every cyber event rendered with full context: target IP + hostname + destination port/proto + application + FortiGate action (color-coded block/allow) + FortiGuard CR score + policy ID + Wazuh rule level + agent name + aggregation counters (deny/unique targets/window).
Orchestrated Mitigation: RTBH / FlowSpec / CF MT
Three tools, one engine. RTBH (SSH Juniper + Huawei, BGP 65535:666) for /32-/24 blackholes. BGP FlowSpec (RFC 8955/8956) for surgical rate-limit/redirect/drop. Cloudflare Magic Transit on-demand for volumetric scrubbing. Median 17 seconds from detect to router commit.
ML + NIST/MITRE Tier-1 Detectors
18 unsupervised ML models: 17-feature IsolationForest, K-Means auto-k, Holt-Winters, Markov path-norm, temporal embeddings, beaconing detector. Plus 5 NIST/MITRE Tier-1: QUIC C2, Protocol Mismatch (T1572 tunnels), DGA/Fast-Flux, Encrypted C2 (JA3), BGP-Traffic correlation.
ANIE — 6-Layer Autonomous AI
Claude-powered autonomous intelligence engine. Every AI decision logged with reason, playbook, confidence score. 90-day audit trail for NIS2/DORA. Pre-anonymised prompts, EU endpoint, no training retention. Local-model fallback available for full data isolation.
Command Center & Public Transparency
📺 NOC / SOC Wallboard →
A wall display built for the room: incidents, mitigations, peers, traffic and the campaigns being blocked right now.
🎯 War Room →
Every attack campaign by origin AS across every vector, AS reputation 0–100, and rung 4: the whole AS blackholed when the per-IP ladder is losing.
🚨 Incidents & Playbooks →
Anomalies become incidents with a MITRE-tagged playbook attached — 61 playbooks decide what is investigated, mitigated or only recorded.
📜 LoA Verifier →
Letters of authorisation signed with Ed25519 and verifiable by anyone at a public URL — the paperwork of peering, made tamper-evident.
🟢 Live public status page & status badge
A public status page with BGP health, peers, prefixes and 24-hour cyber activity — aggregates only, refreshed every 60 seconds — and a live SVG badge you can embed anywhere.
Embed the badge: <img src="https://routepulse.goline.ch/api/v1/badge.svg">
BGP Intelligence
⚠️ BGP Anomaly Detection →
Nineteen routing anomaly classes — MOAS, sub-prefix hijack, route leak, AS-PATH loop, bogon, ASPA invalid — detected on your live table and corroborated with RIPE RIS.
🛡️ RPKI + ASPA →
RPKI validation on every path and ASPA (RFC 9234) route-leak detection, with invalid routes listed and explained, ROA lifecycle monitoring and an audit view.
🌐 AS Explorer & Topology →
Every autonomous system with its prefixes, relationships, traffic, security badges and reputation, one click from any alert; animated topology and path analysis.
👁️ External Visibility & Prefix Monitoring →
How the Internet sees your prefixes, live from RIPE RIS, with alerts when a prefix disappears, moves or is announced by someone else.
🗂️ IRR Audit & RIPE DB Editor →
Route objects cross-checked against what is actually announced, and the RIR estate edited from the NOC with a three-gate safety net.
Flow Analytics & Traffic
📊 Traffic Analytics →
Per-interface, per-peer and per-AS breakdowns, protocol mix, IPv4/IPv6 split and DPI application classification on flows you can reconcile with SNMP.
🧬 Flow Analyzer →
Ask the flow table anything: live mode, filters on every field, drill-down from a peak to the hosts that caused it.
🌊 Traffic Sankey →
Where your traffic really goes, source to destination, as a living flow diagram with particles.
📈 Capacity Planning →
95th-percentile billing, forecasts, commit burn and thresholds per source and per peer — with anomalies when the trend breaks.
💶 Transit Cost & Weathermap →
What each transit really costs, when it runs out, and a live weathermap of the network as it is right now.
Peering & ISP Management
🤝 Peering Analytics →
Peering candidates ranked by real traffic and AS-path adjacency, enriched with PeeringDB, so the next session pays for itself.
Threat Detection & Intelligence
🧮 5-Pillar Threat Scoring →
Cyber events, behaviour, machine learning, reputation and feeds fused into one 0–100 score for every host that touches your network.
🧠 ML Brain — 21 models →
Isolation forest, Markov chains, beaconing, graph change and more; an ensemble with ADWIN/DDM drift detection and per-role baselines.
🃏 Host Intelligence →
A card and a behaviour diary for 966 K hosts: what it did, when the score moved, and why. Two-tier AI assessment where a verdict would change a status.
🕵️ ANIE, AI Analyst & AI Insights →
An autonomous SOC pipeline that investigates correlations, a chat analyst that runs tools on your real data, and scheduled digests with the measured flow section.
Active Defense
⚡ Automated Mitigation & Conviction Engine →
A 5-tier ladder — observe, monitor, rate-limit, FlowSpec, RTBH — driven by SPRT, Thompson sampling and conformal guarantees, executed over SSH on your core routers.
🔐 RA-VPN Siege Ladder (Cisco Secure Firewall) →
The firewall as sensor and actuator: managed shun at 3 real failures, slow-spray catch, /24 at the second IP under siege, origin AS upstream. Default group sinkholed by API.
📧 Mail, FTP & Malware Defense →
Credential stuffing on Exchange read per account, FTP hammering, perimeter AV blocks attributed by direction — the source is blocked upstream, not just the file.
Identity & Endpoint Hygiene
Compliance & Trust
🇪🇺 NIS2 in one click →
Three-stage filing (24 h / 72 h / 30 d) to 30 EU regulators, DORA Article 17 classification, all Ed25519-signed.
AI Economics & Platform
Integrations & SIEM
🧱 Firewalls as sensors and actuators →
FortiGate rich attack context and FortiAnalyzer, Cisco FTD threat detection and shuns managed by RoutePulse, Kemp LoadMaster WAF.
Pricing & Value
🟢 Starter — €6,480 one-off
1 ASN · small fleet · core BGP + traffic + cyber + NIS2.
🔵 Professional — €19,480 year 1, then €4,490/yr
Full platform · NOC + SOC + AI + mitigation + compliance. Replaces roughly €85K/yr of tooling on a mid-size ISP (Crosswork, IDS operations, monitoring).
🟣 Enterprise — €38,980 year 1
Large fleet · priority support · custom integrations.
⚖️ Where it lands (mid-tier, year 1)
Kentik $120,000+ · Cisco Crosswork $72,000 · ThousandEyes $150,000+ · FastNetMon ~$3,588 (DDoS only) · DIY stack ~€40,000 of engineer time — every year. RoutePulse: €19,480 once, €4,490 from year 2, on hardware you own.
One platform vs. four vendors
| Capability | RoutePulse | Kentik | Cisco Crosswork | FastNetMon | Wazuh/Splunk |
|---|---|---|---|---|---|
| BGP + flow + RPKI/ASPA | ✓ | ✓ | partial | ✗ | ✗ |
| Capacity + transit-cost modelling | ✓ | ✓ | ✗ | ✗ | ✗ |
| Peering intelligence + IXP / LoA | ✓ | partial | ✗ | ✗ | ✗ |
| Cyber scoring + SIEM + AI | ✓ | ✗ | ✗ | DDoS | SIEM only |
| Auto-mitigation (RTBH / FlowSpec) | ✓ | ✗ | ✗ | ✓ | ✗ |
| Credential & campaign defense (mail · VPN · FTP · origin AS) | ✓ | ✗ | ✗ | ✗ | detect only |
| Router config-integrity | ✓ | ✗ | ✗ | ✗ | logs only |
| Government CTI at the source (CISA AIS) | ✓ | ✗ | ✗ | ✗ | ✗ |
| Published detection accuracy (AUC) | 0.994 | ✗ | ✗ | ✗ | ✗ |
| NIS2 / DORA / AI-Act built-in | ✓ | ✗ | ✗ | ✗ | ✗ |
| On-prem · data sovereignty | ✓ | ✗ | ✗ | ✓ | varies |
| Scope of the licence | NOC + SOC + compliance | observability | BGP monitoring | DDoS only | log SIEM |
| Price (mid-tier / year) | €19,480 Y1 · €4,490/yr after | $120K+ | $72K | ~$3.6K | $$$ |
Only RoutePulse covers the NOC and the SOC in one line item — and it is the only one of the five that ships the conviction engine, self-defending routers, credential-attack defense and built-in EU compliance. Published list prices, mid-tier, year 1.
Built for Enterprise
Bloom filter, 52K+ indicators
Automated mitigation response
Four-tier resolution chain
Materialized views, optimized storage
From $282/day to $1-3/day
Zero packet loss ingestion
500 features, 136 pages, 67 tRPC routers, 1,156 endpoints. Designed and built entirely in-house. High-performance binary protocol parsers, columnar analytics engine (44 ClickHouse tables — 35 base + 9 materialised views, 1.6B+ rows), real-time streaming architecture, 18-model ML ensemble with adaptive learning and CAD compositional anomaly detector (90% noise reduction on multi-modal hosts), 8-Gate Conviction Engine (SPRT + Thompson Sampling + Conformal Prediction with provable FDR bounds), 47 MITRE ATT&CK playbooks with agentic AI response (ANIE 6-layer Claude pipeline, €1–3/day spend), and native SIEM integration (Wazuh + Suricata IDS + FortiGate IPS with rich attack-context panels). AES-256-GCM encryption at rest, RBAC access control, WORM cryptographically-chained audit trail (append-only hash chain), NIS2 / DORA / AI-Act compliance dossier generator with Ed25519 signed manifests + SHA-256 hash-chained audit entries, public QR-scannable Letter of Authorization verifier.
Built for AS202032
RoutePulse is engineered and operated by the GOLINE SOC team — providing 24/7 BGP analytics, threat intelligence, and automated defense for our network infrastructure.
Visit RoutePulse Try the Public Looking Glass