AS Explorer — Per-ASN Traffic, Peering & Security Posture
“What do we know about AS54321?” is a question network engineers ask every day — peering candidate evaluation, transit cost analysis, abuse-report triage, hijack post-mortem. The AS Explorer answers it in one view: originated prefixes, transit relationships, PeeringDB enrichment, observed traffic, IXP presence, RPKI / MANRS / ASPA security posture, reputation history, and an interactive Cytoscape.js topology graph — all keyed by ASN and refreshed on a 6-hour sync cycle from authoritative upstream sources.
For non-local ASNs the explorer presents originated and transit prefix counts, upstream and downstream relationships, and PeeringDB enrichment (Type, Traffic, Scope, Policy, IXP count). The CAIDA AS-Relationship dataset powers the relationship intelligence with approximately 722,000 relationships refreshed daily, mapping providers / customers / peers for every visible ASN. For local ASNs a dedicated view splits Transit Providers from Upstream ASes, displays received (non-originated) prefixes, and identifies transit-only first-hop indicators. Five detail tabs — Overview, Transit Prefixes, Graph, IXPs, Traffic — provide exhaustive drill-down, and the four security badges (RPKI / MANRS / ASPA / Reputation) appear across every view so operators see security posture at a glance without leaving the page. A dedicated side-by-side AS comparison tool surfaces routing, security, traffic, and IXP differences between any two ASNs in a single screen.
Four security badges — visible everywhere
Every ASN reference across the explorer (and indeed the rest of RoutePulse) carries four security badges: RPKI (per-AS coverage percentage from ~830K VRPs), MANRS (~1,450 participants list), ASPA (RFC 9234 provider authorization — ~1,200 pairs), and Reputation (RoutePulse-internal score derived from blocklist hits, hijack history, AbuseIPDB correlations). The badges are not decorative — they feed anomaly scoring, the 8-gate Conviction Engine, and the AI investigation pipeline. A 6-hour refresh cycle keeps them current without hammering upstream APIs.
CAIDA-powered relationship intelligence
~722,000 provider / customer / peer relationships from the CAIDA AS-Relationship dataset, refreshed daily, give the explorer authoritative upstream / downstream context for every observed ASN. Non-local AS view: originated and transit prefix counts plus PeeringDB enrichment (Type, Traffic, Scope, Policy, IXP count). Local AS view: Transit Providers split from Upstream ASes, received prefix counts, and transit-only first-hop indicators flagging ASNs only reachable through transit (peering candidates).
Five-tab deep drill-down + Cytoscape topology
Five detail tabs cover every angle: Overview (50+ upstream / downstream badges with relationship distinction), Transit Prefixes (paginated table), Graph (Cytoscape.js force-directed layout at depth 1 / depth 2, capped at 200 nodes and 500 edges for performance), IXPs (Name / Speed / IPv4 / IPv6 / RS Peer), and Traffic (inbound/outbound gradient with protocol/application breakdown from ClickHouse). The topology graph renders peer relationships visually so operators see at a glance whether an AS is a transit hub, a stub customer, or an IXP-connected peer.
Side-by-side AS comparison
The AS Comparison tool selects any two ASNs and renders side-by-side panels covering routing (originated / transit prefix counts, common prefixes, AS-PATH overlap), security (all four badges, expanded), traffic (observed bytes in / out by protocol + application), and IXP presence (common IXPs, exclusive IXPs). Peering candidate evaluation, transit alternative analysis, and abuse-report triage become single-screen tasks instead of multi-tab spreadsheet builds.
Key Capabilities
- Comprehensive per-AS intelligence: originated prefixes, transit relationships, security badges, topology, traffic, IXP presence
- Non-local AS view: originated/transit prefix counts + PeeringDB enrichment (Type, Traffic, Scope, Policy, IXP count)
- Local AS view: Transit Providers split from Upstream ASes, received prefix counts, transit-only first-hop indicators
- CAIDA AS-Relationship dataset with ~722K relationships and daily refresh (providers / customers / peers)
- Interactive Cytoscape.js topology graph with force-directed layout at depth 1 / depth 2, capped at 200 nodes / 500 edges
- 5 detail tabs: Overview · Transit Prefixes · Graph · IXPs · Traffic with direction gradient and protocol/application charts
- Four security badges per ASN: RPKI coverage % · MANRS (~1,450 participants) · ASPA RFC 9234 (~1,200 pairs) · Reputation score
- 6-hour refresh cycle from PeeringDB SQLite local mirror (44 MB) with sub-millisecond query latency
- Relationship badges with visual distinction: Transit Provider (yellow) vs Peer (cyan) vs Customer
- Traffic tab with inbound / outbound split, protocol / application breakdown, and timeline from ClickHouse
- BGP route analysis: AS-PATH evolution, MED, LOCAL_PREF, communities, observed announcement history
- Reputation history: blocklist hits, hijack history, AbuseIPDB correlations, RoutePulse-internal score derivation
- Side-by-side AS Comparison tool: routing + security + traffic + IXP presence for any two ASNs in one view
- Security badges feed anomaly scoring, the 8-gate Conviction Engine v2, and ANIE AI investigation context
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →