Skip to main content
Goline It Services Logo

News

  • GOLINE SA is excited to announce a new partnership with NetApp, a global leader in cloud data services and storage solutions. This collaboration aims to help organizations modernize their IT infrastructure, streamline data management, and enhance performance across cloud and hybrid environments. Modern Data Solutions for Businesses Through this partnership, GOLINE integrates advanced data management solutions, enabling businesses to securely store, manage, and access critical information across cloud, on-premises, or hybrid setups. Clients can benefit from: Flexible and scalable storage solutions to meet growing data needs Simplified management of cloud and on-premises environments Enterprise-grade security for sensitive and mission-critical data...
  • GOLINE SA is proud to announce a new strategic partnership with Omnissa, a global leader in digital workspace platforms and Horizon Cloud Service solutions. This collaboration marks a significant step forward in helping organizations embrace secure, flexible, and high-performance work environments. Why Choose Omnissa for Your Business? The platform enables virtual desktops, applications, and unified endpoint management. Organizations can deploy scalable workspaces across cloud, hybrid, or on-premises setups. Key benefits include: Easy access to desktops and apps on any device Centralized management for Windows, macOS, iOS, Android, and ChromeOS Strong security with access controls and multi-factor authentication Automated scaling to...
  • Goline is proud to announce a strategic partnership with Cloudflare, the world leader in web performance and security solutions. This collaboration aims to provide goline.ch customers with state-of-the-art protection against cyber threats while delivering lightning-fast website performance. Through this partnership, Goline integrates Cloudflare’s advanced services, including DDoS protection, CDN caching, DNS security, and edge computing, allowing businesses to secure and optimize their websites effortlessly. Users will benefit from improved page load speed, enhanced reliability, and robust defense against malicious attacks. This partnership with Cloudflare enables goline to offer unmatched security and performance solutions to clients. By leveraging Cloudflare’s cutting-edge technology,...

RoutePulse — Complete BGP Analytics & Security Intelligence Platform

RoutePulse
Your NOC sees routes. Your SOC sees threats.
RoutePulse sees both — and acts with mathematical proof.
18-model ML ensemble feeding an 8-gate Conviction Engine: SPRT + Thompson Sampling + Conformal Prediction. First BGP+security platform with provable false-positive bounds. 47 MITRE ATT&CK playbooks. CAD compositional detector (90% noise reduction). QR-scannable LoA. NIS2/DORA/AI-Act dossier.
BGP hijack confirmed by traffic shift? Blackholed in <3 s. Encrypted C2 over QUIC? Flagged. DGA botnet fan-out? Contained. Multi-modal FortiGate anomaly? CAD 90% noise-cut.
18 ML models. 8-gate Conviction Engine. 5-pillar threat scoring. Conformal Prediction with provable FDR bounds. 84% false-positive reduction on production AS202032.
<3s
Threat Response
56+
Anomaly Types
18
ML Models
47
MITRE Playbooks
963
API Endpoints
90%
CAD Noise Reduction
The first platform purpose-built for ISP SOC/NOC convergence · Self-hosted · Swiss-engineered by GOLINE SA (AS202032)

Watch the 7-minute narrated tour

34 production dashboards, US English audio walkthrough. BGP analytics, ML brain, threat map, NIS2/DORA/AI-Act compliance dossier — the whole platform end-to-end.

From the first suspicious flow to BGP blackhole
in under 3 seconds — fully autonomous.

🔍
NOC + SOC Unified Console

Your NOC sees a route flap. Your SOC sees a threat actor. RoutePulse sees both — and correlates them. BGP hijack + traffic shift = confirmed attack, not two separate tickets in two different tools.

🤖
AI-Powered SOC Analyst

Works 24/7 alongside your team — investigating every critical alert, correlating 39 threat feeds, and orchestrating a 18-model ML pipeline across 56+ anomaly types.

8-Gate Pipeline: Detection to Blackhole in <3s

IP validation → Infrastructure check → ASN whitelist (22 CDN) → Volume gate → ThreatClassifier (10 classes) → TOCTOU lock → Router SSH → Claude AI Arbiter. Every gate must pass. Zero collateral damage on production routers.

Built for the scale of a full Internet routing table — 1.28M+ prefixes, 870K+ hosts, 40K+ flows/min — with 180 days of instant-query retention. No sampling. No blind spots. No compromises.

Why NOC & SOC Teams Choose RoutePulse

Six capabilities that turn your NOC and SOC into a single autonomous defense platform
🧠
18-Model ML Ensemble

3-tier architecture: Core (Baseline, IsoForest, Markov, K-Means, Holt-Winters, Latency, ThreatIntel, Temporal, Beaconing, GraphChange), Specialized (CarpetBomb, DnsTunnel, Reflector), Tier 1 Expansion (QUIC Anomaly, Protocol Mismatch, BGP-Traffic Correlation, DGA/FastFlux, Encrypted C2 Profiler). Self-tuning via TP/FP feedback loops with precision-based adaptive learning. 56+ anomaly detection types across 8 MITRE ATT&CK categories.

Autonomous AI SOC Analyst (ANIE)

6-layer AI engine: L1 MITRE ATT&CK enrichment, L2 autonomous investigation, L3 continuous threat hunting, L4 ML orchestration, L5 self-tuning, L6 persistent network memory. Budget-aware at $1–3/day after 4-layer digest optimization.

🎯
5-Pillar Unified Threat Score

183-point composite across Cyber Events (48pt), Behavioral (40pt), ML Ensemble (30pt), External Intelligence (40pt), and FeedIntel (25pt). 15 correlation rules auto-classify severity and trigger mitigation.

52K+ Indicators, Sub-Microsecond Lookup

39 threat feeds loaded into Bloom filter for <1μs correlation against every flow. MISP integration (4,894 events, 9.9M attributes), AbuseIPDB, Shodan, and commercial blocklists in real time.

💾
1,300x Query Acceleration

Columnar analytics engine with 17 materialized views and 9.5x compression. TopTalkers from 17s to <1s, IP lookups from 8s to 98ms. 180 days of full retention at 3.5TB, instantly queryable.

🛡
Automated Blackhole Mitigation

RTBH (Remote Triggered Black Hole) for IPv4 (/32, /24) and IPv6 (/128) via persistent SSH to Juniper MX and Huawei NetEngine routers. BGP community 65535:666 upstream signaling to 6 transit providers (RFC 7999). AI-driven NEUTRALIZE / OBSERVE / SAFE verdicts, 8-gate safety pipeline with Claude AI Arbiter, progressive ban escalation (7d to 365d), 22-ASN cloud protection, PIN auth. Cloudflare Magic Transit on-demand DDoS protection for prefix-level defense. Alert to blackhole in <3 seconds.

Who is this for?

Built for both sides of the screen

Whether you're keeping the network lit (NOC) or keeping the attackers out (SOC), RoutePulse speaks your language. One platform, two daily rituals.

📡

For the NOC

Network Operations

Real-time visibility from Layer 3 to Layer 7. Know where your traffic goes before a customer calls. Full-Internet RIB (1.28M prefixes), BMP Loc-RIB (RFC 9069, post-policy FIB), BGP-LS topology (RFC 7752), sFlow/IPFIX/NetFlow with 1,575 DPI app signatures, SNMP-powered weathermap, capacity planning with P95 billing — in a single pane.

See NOC tools ↓
🛡️

For the SOC

Security Operations

Hunt, correlate, mitigate. 18 unsupervised ML models + 5 NIST/MITRE Tier-1 detectors find 0-days your signature feeds miss. Conviction Engine (SPRT + Thompson Sampling + Causal Verification + Claude arbiter) cuts false-positive blackholes by 84%. One-click mitigation across RTBH, BGP FlowSpec and Cloudflare Magic Transit — median 17 seconds from detect to router commit.

See SOC tools ↓
NOC · Network Operations

📡 Keep the Lights On

Six daily NOC questions — and the page that answers each one in under 5 seconds.

«Where's my traffic?»
Traffic Analytics + Flow Analyzer

Live sFlow/IPFIX/NetFlow parsing into ClickHouse (35 tables, 9.5× compression). 1,575 SolarWinds-sourced app signatures via DPI. Top ASNs, IXP community attribution (SwissIX, MIX-IT, MINAP), per-protocol breakdown, Wireshark-style ad-hoc filter.

«Is the policy doing what I think?»
BMP Loc-RIB (RFC 9069)

Ingest the router's post-policy FIB as a first-class BMP feed. ~218K prefixes live on MX204 — the routes the router actually installs, with the AS-PATH, communities and RPKI status it actually uses.

«Are we about to saturate?»
Capacity Planning & Forecast

P95 billing tracker per-provider, cost-per-Mbps comparison, CDR utilization, 6-month historical trends, what-if simulator. Capacity-threshold anomaly alerts with 60-min cooldown.

«What does the IGP look like?»
BGP-LS Topology (RFC 7752)

Link-state NLRI ingestion with 2000-entry ring buffer. Interactive d3-force graph: nodes, links and prefixes straight from the IGP. Junos / Huawei VRP / Cisco IOS-XR terminology cross-reference documented.

«Are my peers healthy?»
Peer Health + Loc-RIB Monitors

BMP session uptime badges, flap detection with history, down-since timestamps, per-peer prefix counts. Auto-emailed outreach on 3-day-down via Peering Manager — GOLINE-branded templates.

«Did my prefix disappear globally?»
External BGP Visibility

RIPE RIS Live WebSocket across 23 global vantage points. Mismatch + hijack detection, propagation trace, Last-Seen timestamp, monitored prefix watchlist with alerts on visibility changes or withdrawals.

SOC · Security Operations

🛡️ Hunt, Correlate, Mitigate

Six daily SOC questions — and the answer in ML, correlation and one-click mitigation.

«What's attacking me now?»
Unified Cybersecurity Dashboard

5-pillar host scoring (Cyber + Behavioral + ML + External + FeedIntel, 0–100), 18 ML models, 42 configurable flow rules, 39 threat feeds (52K+ IoCs). Cross-source from Wazuh SIEM + Suricata IDS + FortiGate + AbuseIPDB + Shodan + Nmap parallel.

«Real enough to blackhole?»
Conviction Engine (SPRT + Thompson + Causal)

Five pillars must agree: Sequential Probability Ratio Test to 99% confidence, Thompson Sampling exploration, Causal Verification, 22 CDN/cloud ASN whitelists + 4-layer SSH protection veto, Claude AI arbiter final review. 84% fewer false-positive blackholes.

«FortiGate + Suricata + Wazuh in one view?»
Security Events Cross-Source

Every cyber event rendered with full context: target IP + hostname + destination port/proto + application + FortiGate action (color-coded block/allow) + FortiGuard CR score + policy ID + Wazuh rule level + agent name + aggregation counters (deny/unique targets/window).

«Null-route without 6 SSH sessions?»
Orchestrated Mitigation: RTBH / FlowSpec / CF MT

Three tools, one engine. RTBH (SSH Juniper + Huawei, BGP 65535:666) for /32-/24 blackholes. BGP FlowSpec (RFC 8955/8956) for surgical rate-limit/redirect/drop. Cloudflare Magic Transit on-demand for volumetric scrubbing. Median 17 seconds from detect to router commit.

«0-day with no known signature?»
ML + NIST/MITRE Tier-1 Detectors

18 unsupervised ML models: 17-feature IsolationForest, K-Means auto-k, Holt-Winters, Markov path-norm, temporal embeddings, beaconing detector. Plus 5 NIST/MITRE Tier-1: QUIC C2, Protocol Mismatch (T1572 tunnels), DGA/Fast-Flux, Encrypted C2 (JA3), BGP-Traffic correlation.

«Why did the AI decide that?»
ANIE — 6-Layer Autonomous AI

Claude-powered autonomous intelligence engine. Every AI decision logged with reason, playbook, confidence score. 90-day audit trail for NIS2/DORA. Pre-anonymised prompts, EU endpoint, no training retention. Local-model fallback available for full data isolation.

ISP Infrastructure Manager

Two tightly-coupled operator tools that previously lived outside RoutePulse: generating Letters of Authorization for cross-connects, and tracking patch-panel inventory across every GOLINE datacenter. Consolidated into the platform with full audit trail, PeeringDB-driven autocomplete, encrypted Equinix API integration, and email delivery.

📄
Letter of Authorization generator

Fill a structured form, the PDF is produced server-side (A4, GOLINE-branded, legal wording, verification code in accent blue). Quick Select chips for configured DCs, manual PeeringDB autocomplete for any new facility. Requester dropdown driven by the local PeeringDB Postgres mirror (34k networks + 1.3k IXPs + 276 carriers). Address auto-fills via PeeringDB org → RIPE REST → ARIN REST → RIPEstat chain. Every LoA is persisted with full audit (who issued it, when, to whom, from what cross-connect) and the PDF blob lives in the DB so it can be redownloaded or re-sent without regenerating.

📡
Patch-panel inventory, one per datacenter

Per-DC card with Our Equipment details (Customer / Account / IBX / Cage / Cabinet / Patch Panel / Default Port / Room / Media / Rack Location / Provisioning flags) and a full-width port status grid with per-port tooltip (customer name + install date + order number). Edit mode (admin) unlocks the ports table with Lock/Unlock toggle, per-port Status / Customer / Install Date / Media / Order Number fields, Clear Port action with a confirmation dialog, and a Set Port Count prompt that resizes the array — essential for datacenters like MIX DC Caldera which have no Colocation API and require manual port entry.

📶
Equinix Colocation API sync

One-click “Sync with Equinix” on the Equinix ZH2 card pulls the current availability of the patch panel over OAuth2 (client credentials flow, token cached in memory with refresh 60s before expiry). Smart merge preserves the customer / install date / order number fields on occupied ports — only the Equinix-reported “available” set is trusted. Credentials live encrypted in Postgres (AES-256-GCM, keyed by ENCRYPTION_KEY) and are editable + test-able from the UI, never in .env in production.

Email delivery with NOC auto-fill

Send the generated LoA to the counterparty with one click — the To field is pre-filled by looking up the recipient’s NOC / Technical contact through the new PG mirror of PeeringDB’s POC table (23k contacts). The picker uses a combined ranker: role label + email local-part pattern, so noc@ always wins even when the PeeringDB role happens to be Maintenance. Email body is a formal cover with a 14-row cross-connect summary table plus an optional operator message block, signed by the authorized signatory from Company settings. PDF attached. Reuses the existing GOLINE-branded email template so every outbound looks consistent with the rest of RoutePulse.

💾
PeeringDB → Postgres mirror (shared)

A complete mirror of PeeringDB’s data into 9 indexed Postgres tables (33k orgs, 5.9k facilities, 34k networks, 1.3k IXPs, 276 carriers, ~70k join rows, 23k NOC/tech POCs). Full refresh in ~8.5s via a single TRUNCATE + chunked INSERT transaction, auto every 6h (1–168h configurable). Chain-triggered from Settings → Caching after every SQLite sync. Facility autocomplete, network+IX presence, and NOC lookup served in 30–50ms from the local PG mirror — the old path hitting the PeeringDB REST API took 30–60s per facility.

📑
Shared WHOIS AS-details cache

New structured WHOIS cache (org name, address, phone, country) per ASN with a 30-day TTL, populated lazily on demand through the fallback chain RIPE REST → ARIN REST → RIPEstat → PeeringDB /net?asn=. Shared between the ISP Manager (for LoA auto-fill) and the rest of RoutePulse (AS Explorer enrichment, host intelligence). Settings → Caching has a new “AS Organization Details (shared)” section with a Test Lookup box to force-refresh a single ASN and inspect the resolved org / address / source live.

BGP Intelligence

Full Internet routing table analysis with real-time anomaly detection across 1.28M+ prefixes
Go
Go Collector Engine
16MB binary, goroutine-per-router, 34+ query types, SSE events
🔍
RIB Search
1.28M+ prefixes, best-path, communities, RPKI badges
🔎
Looking Glass
Instant prefix lookup with longest-match, per-peer comparison
Path Analysis
AS-to-AS animated Canvas flow with IP Intelligence dashboard
👥
Peer Management
Card layout by role, RIB dump status, SNMP state, peer compare
📖
Community Decoder
18 transit + 8 IXP dictionaries, large community RFC 8195
📊
AS Topology Graph
interactive SVG with glow filters, CAIDA roles, depth 1-3
📈
Routing Trends
Prefix growth, AS-PATH length, unstable prefix ranking, 24h-90d
Path Timeline (BGPlay)
Animated AS-PATH changes with play/pause/speed controls
AS Comparison
Side-by-side routing, security, traffic, IXP presence analysis
Stale Detection
Router/peer inactivity with configurable thresholds
MOAS Whitelist
Known multi-origin pairs for CDN/anycast FP suppression

Flow Analytics & Traffic

Multi-protocol flow collection and deep packet inspection processing 40K+ flows/min at wire speed
📡
Flow Collector
sFlow v5 + IPFIX/NetFlow v9, 5 active sources, auto sampling
💾
Columnar Storage
35 tables, 17 MVs, ZSTD 9.5x compression, 180-day TTL
🔬
DPI Classification
1,575 apps, 272 port rules, ~92% classification rate
🔧
Flow Query Builder
Kentik-level ad-hoc queries, stacked time series, CSV export
🌍
GeoIP Heatmap
City-level MaxMind mapping, country tables, host overlay
🗺
Weathermap
NOC-style SVG topology, SNMP throughput, animated dashes
🔄
RIB Correlation
Real-time BGP enrichment, 4-tier LPM, 100% enrichment rate
💰
IXP Community Attribution
SwissIX/MIX-IT/MINAP community-based traffic split

Security & Compliance

Multi-layer defense with RPKI validation, threat intelligence, behavioral scoring, and automated mitigation
🔒
ASPA Validation
RFC 9582 route leak detection, 4,040 provider pairs
📜
ROA Lifecycle
VRP diff engine, expiry badges, optimizer suggestions
🧪
Behavioral Scoring v3
14 components, 9 parallel CH queries, max 40pts
📢
Threat Feed Intelligence
39 feeds, Bloom filter, MISP 4,894 events, CISA AIS
🛡
Wazuh SIEM
Suricata IDS + FortiGate IPS + cross-source correlation, 18M+ alerts
🚫
Progressive Ban System
Strike escalation 7d-365d, observation window, auto-re-ban
🚨
Bogon Detection
14 IPv4 + 9 IPv6 bogon ranges, critical severity alerts
Cloud ASN Protection
Google/Cloudflare/AWS/Meta never blackholed, smart gates
🔍
AbuseIPDB Integration
Confidence scoring, auto-reporting, 23 category mappings
📱
Shodan Integration
Open ports, CVE list, OS detection, cloud provider ID
🌐
IXP LAN Leak Detection
2,500+ IXP LAN prefixes, DFZ leak monitoring
🏷
AS Security Badges
RPKI, MANRS, ASPA posture per ASN across all views
🛡
Suricata IDS Native
9 event types, severity-gated, noise SID filtering, MITRE enrichment
🔥
FortiGate IPS Ingestion
CEF parser, IPS/UTM alerts, crscore, FortiGuard links
🔭
Nmap Attacker Scanner
Top-200 ports, OS detection, service versions, Pillar 4 scoring
MITRE ATT&CK Mapping
Auto-enrichment from Suricata + Wazuh rules, tactic badges
🔗
4-Tier ASN Resolution
GeoIP + Flow + RIB LPM + Peer table = 100% coverage
📡
Discoveries Tab
Live host discovery feed with source, direction, SIEM correlation

Threat Detection Expansion

Based on NIST SP 800-41/207, MITRE ATT&CK, and CISA research — 5 new ML detectors, 8-gate blackhole pipeline, Claude AI Arbiter
🧠
ThreatClassifier (10 Classes)

Class-driven mitigation: 10 threat classes (noise, recon, behavioral, c2_suspect, c2_confirmed, tunnel, botnet, volumetric, amplification, carpet_bomb) routed to 3 defense layers. Replaces score-threshold blackholing.

🤖
Claude AI Arbiter (Gate 8)

Final safety gate: Claude Opus 4.6 asks “can the FortiGate handle this?” before any BGP blackhole. Safe-side default: AI unavailable = DENY. ~bash.30/day. Full audit trail.

🛡
8-Gate Blackhole Pipeline

IP validation → Infrastructure → ASN whitelist (22 CDN) → Volume gate → Classification → TOCTOU → Router SSH → AI Arbiter. Every gate must pass.

🔍
5 New NIST/MITRE Detectors

QUIC Anomaly (encrypted C2 on UDP/443), Protocol Mismatch (T1572 tunnel detection), BGP-Traffic Correlation (ISP-unique hijack confirmation), DGA/Fast-Flux (botnet fan-out), Encrypted C2 Profiler (JA3 + flow).

🌐
PTR Auto-Protection

DNS reverse lookup auto-protects RIPE Atlas (377+ hosts), DNS Root Servers, RIPE NCC, NLNOG RING. Toggleable from Settings GUI.

Configurable Safety Gates

Volume Gate (1MB–1GB), AI Arbiter toggle, Early Release (auto-release when threat subsides), 22 CDN/cloud ASN whitelist — all adjustable from Settings.

Observability & Platform Hardening

Native event-loop instrumentation, on-demand CPU profiling, persistent sessions, tuned PostgreSQL, 5-minute license heartbeat
📈
Native Event Loop Instrumentation

Libuv-level event loop delay histogram + CPU utilization ratio + post-major-GC heap sampling via Node.js perf_hooks, always-on at <0.1% overhead. Direct UI-freeze measurement — 11 new Prometheus gauges surface max, p50/p95/p99, utilization, and GC pauses.

🔎
On-Demand CPU Profile & Heap Snapshot

V8 inspector.Session endpoints capture .cpuprofile (5–120s) and .heapsnapshot into /tmp, downloadable via admin-gated endpoint with filename allowlist. Line-level flame graphs in Chrome DevTools or speedscope.app — no –inspect flag, no external port, runs on the live production process.

📊
Profiler Dashboard (4 Tabs)

Settings > Profiler: Overview (4 health KPI cards with threshold colouring + SVG sparklines + GC summary + top 5 hottest spans), Spans (detailed table), Profiling Tools (CPU profile + heap snapshot buttons + captures list), Configuration. Everything an operator needs to diagnose a freeze in one page.

Cooperative Yield Helper

profiler.createYielder(thresholdMs) wrapper converts unbounded CPU bursts into bounded-latency bursts without per-call-site setImmediate plumbing. Fast-path is a single Date.now() comparison. Wired into the three heaviest ML inference loops (isolation forest, K-means, temporal embeddings).

🔒
Persistent Session Store

user_sessions PostgreSQL table (token PK + user_id FK CASCADE + denormalised username/role + indexed expires_at) hybrid-cached in memory for O(1) sync reads on every authenticated request. Operator sessions survive systemctl restart — no re-login after every deploy. 30-day TTL, hourly expiry cleanup.

🛢
PostgreSQL Buffer Pool Tuning

shared_buffers 12 GB, effective_cache_size 24 GB, work_mem 64 MB, checkpoint_timeout 15 min, max_wal_size 8 GB on a 47 GB host alongside Node + ClickHouse. Cache hit ratio steady at 99%+. The /metrics endpoint events query was rewritten from count(*) filter(where) full-scan to index-only subselects (8.4s → 1.1s).

🔑
License Server & 5-min Heartbeat

Standalone license authority with Ed25519 signing + clone-resistant hardware UID (SHA-256 of SMBIOS product UUID + machine-id + rootfs UUID + primary MAC). 5-minute heartbeat cadence so revocations propagate fast. 4 editions, admin GUI with audit log, daily SQLite backup.

Transactional Email Branding

Consistent "Powered by RoutePulse" footer with explicit https://routepulse.goline.ch link across every outbound email: peering requests, peering-down notifications, user invites, SMTP tests, AI reports, notification alerts, reminders. Outlook-compatible HTML in every flow.

📡
Auto-Synced Prometheus Version Label

External label routepulse_version in prometheus.yml is rewritten and SIGHUP-reloaded on every release via scripts/release.js. Telegram alerts routed through Alertmanager always show the currently-running build — no more stale version drift across deployments.

BGP Advances & Operator UX

Live BMP Loc-RIB on MX204, BGP-LS link-state topology, FlowSpec mitigation feed, FortiGate rich attack context, SNMP startup grace, runtime profiler toggle, Europe/Zurich timezone correctness
🏭
BMP Loc-RIB Live (RFC 9069)

Ingest the router’s post-policy Loc-RIB as a first-class BMP feed (PeerType=3, synthetic locrib@... peer key). MX204 live in production exposes ~218K FIB prefixes — the routes the router actually installs, not just what it receives from a peer. Dedicated "Loc-RIB Monitors" section on /peers with per-VRF breakdown and prefix count.

🗺
BGP-LS Topology (RFC 7752)

Link-state NLRI ingestion with 2000-entry ring buffer and a dedicated /topology-ls page rendering nodes, links and prefixes via d3-force. Junos, Huawei VRP and Cisco IOS-XR terminology cross-reference documented (link-state / link-state-family / traffic-engineering).

🔎
BGP FlowSpec v4/v6 (RFC 8955/8956)

Full parser for the carrier-grade mitigation protocol used to signal granular rate-limit, redirect and drop rules between ASes. Wired audit-first (log + event + /settings/flowspec review page) so operators validate every upstream rule before it takes effect; the same pipeline is the foundation for originating outbound FlowSpec mitigations to transit providers — more targeted than a /32 blackhole.

🛡
FortiGate Rich Attack Context

Every cyber_siem_fw_* event on /security-events renders a dedicated FortiGate panel: target IP (clickable), target hostname, destination port/proto, application, FortiGate action (color-coded block/allow), FortiGuard CR score & reputation level, policy ID, Wazuh rule level, agent name, plus aggregation counters (deny count, unique targets/ports, time window). Operators can tell at a glance which asset was hit and how severe FortiGuard considered it — without drilling into raw JSON.

BGP Session Startup Grace

Configurable 0–60 min grace window post-restart (default 5) that suppresses snmp_bgp_up / snmp_bgp_down / snmp_unreachable / snmp_recovered dispatches while SNMP polling converges. Internal state tracking still updates so the first post-grace poll has a correct baseline — only the notification side is gated. No more Telegram spam on every deploy.

🎯
Profiler Master Toggle (Hot-Reload)

One-click master switch on /settings/profiler turns the full span profiler on or off without a service restart. Toggling OFF also flushes the ring buffer and client-side history so the UI actually empties out; snapshot polling drops 3s→15s. Near-zero overhead fast path when disabled (single boolean branch per span call) — safe to leave dormant in production.

🕓
Europe/Zurich Timezone Everywhere

Every operator-facing timestamp renders in it-CH locale with explicit Europe/Zurich (CET/CEST). 40+ UI locations and 15+ ClickHouse billing / aggregation queries anchored locally — current-billing-month boundary flips at local midnight, not 02:00 CEST. Shared fmtCET / fmtCETDate / fmtCETTime helper prevents future drift.

AI & Machine Learning

Autonomous SOC analyst with an 18-model ML pipeline and 15 cross-model correlation rules
🤖
ANIE 6-Layer Pipeline
L1 MITRE enrichment, L2 investigation, L3 threat hunting, L5 self-tuning, L6 memory
💬
AI Analyst Chat
Claude-powered BGP investigation with 8 real-time tools
AI Threat Mitigation
7-day flow profiles, NEUTRALIZE / OBSERVE / SAFE verdicts
🧬
Auto-Tune Engine v2
Scanner ASN auto-approve, stale cleanup, threshold tuning
🔗
Correlation Engine v5
15 cross-model rules incl. beacon convergence, lateral movement
💲
AI Cost Optimization
$282/day reduced to $1-3/day, 4-layer digest pipeline
🔮
Threat Intel Model
3-source fusion, 0.18 ensemble weight, 52K+ indicators
📋
ML Host Auto-Categorize
130+ infra hosts from 8 sources, 70+ role categories
🧬
Temporal Embeddings
8-dim per-host behavioral trajectory, Mahalanobis distance
📡
Beaconing Detector
Inter-arrival CV + Shannon entropy, catches jittered C2
🕸
Graph Change Detection
Persistent edge graph, lateral movement, hub formation
🛡
Hijack Impact Simulator
CAIDA BFS, RPKI/ASPA resilience score 0-100, tier analysis
🌍
Outage Correlation
5 signal types, 10-min window, active/recovering lifecycle
BGP Digital Twin
Peer down/add/depreference what-if on live RIB
📋
AI Incident Response
5 playbooks, auto-trigger on CRITICAL, TTD/TTM/TTR SLA
🧪
Red Team Framework
10 attack scenarios, detection matrix, evasion resistance
Conviction Engine
SPRT + Thompson Sampling + Causal Verification, 3-tier
🎓
Active Learning
Uncertainty sampling, operator review prioritization
📊
Evaluation Framework
P/R/F1 per model from ground truth, weekly + boot
📌
Prefix Watchlist
Custom prefix monitoring, origin/path/subprefix alerts
🏥
Host Roles (5-tab)
Uncategorized, Classified, Discovered, Well-Known, Categories
👻
Dark IP Detection
CAIDA ghost method, outbound <0.1% + avg packet <100B
📡
Streaming Telemetry
gNMI/gRPC ready framework, SNMP enhanced, 1s resolution
🔍
Prefix Intelligence
4-tab deep dive: Security, Traffic, Visibility, Anomalies
💪
18/18 ML Scoring
All models contribute to host threat score via AS→IP propagation
Immediate Scoring
18 models on same IP → bypass 2-min timer, instant re-score

Infrastructure & Monitoring

Comprehensive platform operations: health scoring, SNMP polling, probes, and 40 settings pages (fully audited)
📡
SNMP BGP Monitoring
SNMPv2c polling on 6 routers, FSM state tracking, MikroTik API
🎯
Data Plane Probing
ICMP ping, TCP connect, HTTP GET with threshold alerting
🔄
Worker Auto-Restart
Exponential backoff, circuit breaker, DB cleanup on OOM
Service Control Panel
Restart 5 services, CPU/RAM gauges, live log viewer
👤
RBAC User Management
Admin/Viewer roles, email invites, 24h session TTL
🗝
API Key Management
Centralized keys: MANRS, PeeringDB, Shodan, AbuseIPDB, Claude
📦
Cache Management
PeeringDB SQLite, CAIDA, Whois LRU, RPKI VRP pre-warming
📝
Log Level Control
4 levels, file logging with daily rotation, 3-day retention
💾
Backup & Restore
9-table ZIP export/import, atomic transactions, preview panel
🗑
Data Retention
Per-table retention config, daily auto-purge, manual triggers
🔌
WebSocket Push
Socket.io server-push, eliminates 12 req/min per tab
🔒
AES-256-GCM Encryption
Credential encryption at rest, ENCRYPTION_KEY env var

Integration & API

Extensible platform with REST API, monitoring dashboards, MCP server, and 47 notification types across 3 channels
🔔
47 Notification Types
Telegram + Email + Webhook + Recipes across 8 categories
📅
Scheduled Reports
Daily/weekly/monthly via Email, Telegram, Webhook. AI digest 06:00 UTC
📄
Compliance PDF Reports
3 templates, 12 sections, GOLINE branding, PDFKit engine
🌐
REST API (7 endpoints)
/api/v1/ with rp_xxx key auth, 60 req/min rate limit
📊
Prometheus /metrics
40+ metrics: routers, peers, RPKI, flows, ML, anomalies, CPU, RAM
📈
Grafana Dashboard
28-panel template, 7 rows, downloadable JSON, setup guide
🤖
MCP Server
11 tools via Streamable HTTP, Claude Desktop + Cursor support
🔗
Webhook Recipes
Slack blocks, Discord embeds, PagerDuty incidents, Jira issues
📧
Email Templates
GOLINE-branded HTML, Outlook / Gmail / Thunderbird compatible
📡
Live Event Feed
Socket.io broadcast of all system events to connected clients
🔍
AS Enrichment
CAIDA, PeeringDB SQLite, RIPE Whois, GeoIP2, Team Cymru, RDAP
📖
Changelog
In-app 400+ version history with category badges and search

More of what RoutePulse does

The headline sections above are a selection, not the whole toolkit. A curated look at the additional capabilities operators rely on day to day.

Looking Glass

Instant lookup tool: paste an IP or prefix and get every matching route from the live RIB, best path highlighted, with origin AS, AS-PATH, communities, and RPKI status. Supports both exact match and longest-match (covering prefix).

Path Analysis

Animated AS-to-AS path explorer: pick a destination, see how traffic actually flows out of your AS through transit and IXP peers, with particles flowing along each AS-PATH on a zoomable canvas.

Path Timeline (BGPlay)

BGPlay-style animated visualization of AS-PATH changes for a prefix: pick a time window (1h–7d), press play, see paths appear and disappear over time with announce/withdraw color coding, per-path tracking, speed control.

Community Decoder

Decodes BGP community values into human-readable labels using built-in dictionaries for 18 transit providers + 8 IXP route servers (e.g. `7018:1234` → AT&T action).

AS Comparison Tool

Side-by-side comparison of two AS numbers: identity cards (name, country, type), routing stats (prefixes, paths, transit relationship), security badge comparison (RPKI / MANRS / ASPA), CAIDA relationship classification, PeeringDB metadata, traffic vo

AS Topology Graph

Force-directed graph of the AS-level topology around your network: nodes are ASes, edges are paths, colored by role (transit / IXP / peering / customer). Configurable depth (1-3 hops), force vs hierarchical layout, drag/zoom/pan, touch-friendly.

BGP Sankey Diagram

Animated Sankey diagram showing how traffic flows Source AS → Your AS → Destination AS, with particles moving along each link at 60fps. Slider controls path depth, group-by toggle (origin AS / next-hop / IXP), click-to-drill detail panel.

BGP Stats History

A 5-minute snapshot loop captures the key BGP KPIs (IPv4/IPv6 prefix counts, active peer count, updates/sec, RPKI valid/invalid/unknown coverage) into a database table with 90-day retention.

BGP What-If Simulator

Interactive RIB simulation.

Outage Correlation Engine

Automatically groups 7 different signal types (mass withdrawal, peer flap, traffic drop / shift, visibility drop, probe alert, ML baseline deviation) into single outage events per AS, with a sliding 10-min correlation window.

Routing Trends

Long-term routing-table evolution charts: prefix growth (IPv4 / IPv6) over time, average AS-PATH length, unique ASN count, prefix length histograms (/8 through /24+), top unstable prefixes. Period selector 24h to 90d.

BGP-LS Topology

For MPLS-TE backbones, RoutePulse ingests the IGP topology (OSPF or IS-IS Link-State Database) through BGP-LS (RFC 7752).

RIB Explorer

Browse the full Internet routing table (~1.28M IPv4 + IPv6 prefixes) as RoutePulse sees it from your routers.

Router Forwarding-Table Visibility

See exactly which routes a router has chosen to install in its forwarding table — not just the routes received from neighbors.

Flow Query Builder

Ad-hoc query engine in the spirit of Kentik / Akvorado.

Application Classification (DPI)

1,575 application signatures cover ~92% of observed flows. Bidirectional port + protocol matching with O(1) lookup, hostname-based DNS resolution, "match any port" rules for IP-only signatures.

Peering Analytics

Identifies which transit ASes you carry traffic to that have a presence at one of your IXPs — i.e. peering candidates that would let you offload paid transit. Score formula combines absolute traffic volume with prefix breadth, sorted by best ROI.

Peering Manager

Guided email-based peering outreach. Candidates tab ranks potential peers by 24h bilateral traffic and shared IXPs, with status badges (sent / rejected / accepted).

IXP Community Attribution

Tags traffic with which IXP it crossed using BGP community values (20203:2003 = SwissIX, 20203:2004 = MIX-IT, 20203:2005 = MINAP). This catches IXP traffic that the AS-PATH alone wouldn

ClickHouse Storage Layer

All flow data lands in a 15-table ClickHouse layout: 1 raw flows table + 14 materialized views pre-aggregating the heavy queries (peer billing, IXP community attribution, ML hourly-per-AS, etc.).

Multi-Vendor Flow Collector

Receives sFlow v5 (UDP 6344) and IPFIX / NetFlow v9 (UDP 4740) from your routers — auto-detected from the packet header. Currently ingesting from MX204, NE8000, and three MikroTik CCR2004 (SwissIX, MIX-IT, MINAP).

AS Enrichment for IPFIX/NetFlow

IPFIX / NetFlow flows from MikroTik and Juniper inline-jflow often arrive without BGP AS info.

AI Analyst Chat

Conversational BGP investigator backed by Claude with 8 real-time tools: RIB lookup, anomaly search, peer status, traffic summary, RPKI status, network health, AS info, path analysis.

AI Insights

Five proactive AI-generated reports the operator doesn

Machine-Learning Detection Engine

Eighteen ML models in pure TypeScript working as an ensemble.

ML Brain Dashboard

A single ML Brain page with four focused tabs so every artifact lives where it conceptually belongs. Models tab is the System Overview (Brain Canvas, Brain Maturity, 18-Model Knowledge Grid, ML Configuration, System Vitals).

MOAS Whitelist

Whitelist of known legitimate Multi-Origin AS pairs (e.g. anycast prefixes shared by Cloudflare, Google, Akamai) so they don

MISP Integration

Connected to the GOLINE MISP instance (4,894 events, 9.9M attributes, 85 feeds). RoutePulse pulls from the MISP REST API every 15 minutes with the to_ids filter applied.

ASPA Validation

Cryptographic route-leak detection per RFC 9582 using RPKI ASPA objects. RoutePulse walks each AS-PATH hop and verifies provider authorization against ~4,040 provider pairs from rpki-client.org.

Prefix Watchlist

Watch any external prefix for origin change, AS-PATH change, or subprefix announcement. Each prefix has per-event alert toggles, an expected origin AS, live RIB status, and flows through the full notification pipeline.

IRR Cross-Validation

Automated comparison of live BGP routing state against IRR (Internet Routing Registry) route objects via the RIPE REST DB API.

Go Collector Engine

The high-performance Go binary that listens for BGP and BMP sessions from your routers.

Network Weathermap

NOC-style SVG topology of your backbone: FortiGate, MX204, NE8000, the three IXP routers. SNMP-polled interface throughput on each link, with utilization % and capacity labels.

Data Plane Probing

Active verification that your data plane is actually working, not just announced in the RIB.

Webhook Recipes

Pre-built notification recipes for popular destinations so integration with a corporate tool is a single form, not a custom script: Slack (rich message blocks), Discord (embed cards), PagerDuty (automatic incident creation with severity mapping), and

Prometheus Metrics

Over 55 Prometheus metrics exposed in text format, refreshed in the background every 10 seconds so scrapes always return in about 4 ms (previously 11-54 seconds under load).

System API Key

An admin-level API key for CLI automation and testing, auto-generated at boot and authenticated via the `x-api-key` HTTP header. Settings > Integrations exposes an eye toggle, copy button, and regenerate with confirmation.

License Server

Standalone license authority at https://license.routepulse.goline.ch issues, renews, and revokes RoutePulse licenses signed with an Ed25519 keypair.

Cloudflare Magic Transit & RTBH

On-demand DDoS protection and Remote Triggered Black Hole routing — integrated natively into RoutePulse
☁️🛡️ Real-time DDoS Protection

Webhook endpoint receives Cloudflare alerts in real-time (5s Telegram delivery). 11 alert types: L3/L4 DDoS, MNM auto-advertisement, tunnel health, BGP hijack. Smart debounce: 10s for DDoS (consolidates multiple CF webhooks), instant for critical. CF payload parser extracts Gbps/Mpps from all alert formats. Tested with 7 Gbps / 14.5 Mpps real DDoS attacks.

📡 BGP Prefix Management

Advertise/withdraw 5 on-demand prefixes (4 IPv4 + 1 IPv6) with verify-after-write safety (GET confirms PATCH before updating state — prevents BGP blackhole on API failure). Manual advertise skips auto-withdraw. Auto-withdraw check every 15s with instant calm detection from webhooks. 5-retry API resilience (0/3/8/15/30s backoff, 60s timeout).

📋 124 DDoS L3/L4 Rules

Full searchable table of all Cloudflare managed DDoS rules. 70 service presets for custom overrides (Web, VPN, VoIP, Database, Gaming, Industrial/IoT). Simple + Advanced wirefilter editor.

🗄 Tunnels, CNI & Static Routes

GRE/IPsec tunnel + CNI monitoring with near real-time throughput (5-min window from magicTransitNetworkAnalyticsAdaptiveGroups). CNI V2 interconnect status (Equinix ZH4, 10G). DDoS intelligence dashboard: Protection Ratio (pass vs drop), Top Attack Sources (ASN + country), Mitigation Edge Locations (CF PoPs). 14 static routes with priority-based failover.

🎯
RTBH Blackhole (IPv4/IPv6)
Inject/withdraw /32, /24 (IPv4) and /128 (IPv6) via persistent SSH. BGP community 65535:666 upstream signaling.
🧹
Router Route Verification
Live SSH query confirms active blackhole routes on upstream routers. Full audit trail.
Auto-Withdraw Logic
15-minute calm period auto-withdraws prefixes (15s check interval). Attack-end webhook starts countdown instantly. Manual advertise skips auto-withdraw. Verify-after-write prevents state desync.
📊
Attack Statistics
Peak attack tracking, aggregate events (total Mbps/pps/sources), per-prefix history. Smart micro-mitigation filtering (<1000 pps = info, not notified). 8 redesigned Telegram templates with auto Gbps/Mpps formatting.

Built for Enterprise

Performance, reliability, and security at every layer
<1 μs
Threat indicator lookup
Bloom filter, 52K+ indicators
~3s
Blackhole route injection
Automated mitigation response
100%
ASN resolution coverage
Four-tier resolution chain
1,300x
Query acceleration
Materialized views, optimized storage
99%
AI cost reduction
From $282/day to $1-3/day
40K+
Flows/min sustained
Zero packet loss ingestion

400 features, 120 pages, 58 tRPC routers, 965 endpoints. Designed and built entirely in-house. High-performance binary protocol parsers, columnar analytics engine (44 ClickHouse tables — 35 base + 9 materialised views, 1.6B+ rows), real-time streaming architecture, 18-model ML ensemble with adaptive learning and CAD compositional anomaly detector (90% noise reduction on multi-modal hosts), 8-Gate Conviction Engine (SPRT + Thompson Sampling + Conformal Prediction with provable FDR bounds), 47 MITRE ATT&CK playbooks with agentic AI response (ANIE 6-layer Claude pipeline, €1–3/day spend), and native SIEM integration (Wazuh + Suricata IDS + FortiGate IPS with rich attack-context panels). AES-256-GCM encryption at rest, RBAC access control, WORM cryptographically-chained audit trail (append-only hash chain), NIS2 / DORA / AI-Act compliance dossier generator with Ed25519 signed manifests + SHA-256 hash-chained audit entries, public QR-scannable Letter of Authorization verifier.

Built on open standards: MANRS · RIPE RPKI · PeeringDB · MISP · NIST CSF

Built for AS202032

RoutePulse is engineered and operated by the GOLINE SOC team — providing 24/7 BGP analytics, threat intelligence, and automated defense for our network infrastructure.

Visit RoutePulse
GOLINE SA · Via Croce Campagna 2, CH-6855 Stabio, Switzerland · soc@goline.ch