RPKI Validation & ROA Coverage
RoutePulse implements full Resource Public Key Infrastructure (RPKI) validation with approximately 830,000 Validated ROA Payloads (VRPs) loaded from Cloudflare or a custom validator. A 30-minute automatic VRP refresh cycle ensures that route origin validation stays continuously up to date. Every prefix across the platform is classified into one of three validation states: Valid (matching ROA confirming legitimate origin), Invalid (conflicting ROA indicating a potential hijack), or Not Found (no ROA exists). The per-AS RPKI coverage scorecard calculates the percentage of originated prefixes covered by valid ROAs, giving operators immediate visibility into their routing security posture.
The ROA Lifecycle monitoring system includes a VRP diff engine that tracks changes — NEW, REMOVED, and MODIFIED ROAs — with colored badges for rapid identification. ROA optimizer suggestions identify prefixes that could benefit from ROA creation or adjustment, while ROA expiry tracking with countdown badges enables proactive certificate renewal before coverage lapses. Cross-referencing with IRR route objects validates RPKI vs. IRR consistency. ASPA (RFC 9582) provider authorization validation covers approximately 1,200 ASPA provider pairs for route leak detection. The RPKI badge system is woven throughout the entire platform: every prefix and AS displays real-time RPKI status. RPKI data also feeds into anomaly detection confidence scoring, where RPKI-invalid anomalies automatically receive higher severity. This comprehensive validation is essential for MANRS compliance, demonstrating commitment to routing security best practices.
Key Capabilities
- ~830K Validated ROA Payloads loaded from Cloudflare or custom validator for comprehensive route origin validation
- 30-minute automatic VRP refresh cycle ensuring continuously up-to-date validation data
- Per-AS RPKI coverage scorecard showing the percentage of originated prefixes covered by valid ROAs
- Three validation states per prefix: Valid (matching ROA), Invalid (conflicting ROA — potential hijack), and Not Found (no ROA exists)
- Invalid prefix list with origin AS sorting and drill-down for hijack investigation
- ROA Lifecycle monitoring with VRP diff engine tracking NEW, REMOVED, and MODIFIED ROAs via colored badges
- ROA optimizer suggestions identifying prefixes that would benefit from ROA creation or adjustment
- ROA expiry tracking with countdown badges for proactive certificate renewal
- Cross-reference with IRR route objects for RPKI vs. IRR consistency validation
- ASPA (RFC 9582) provider authorization validation with ~1,200 ASPA provider pairs for route leak detection
- Platform-wide RPKI badge system displaying real-time RPKI status on every prefix and AS
- RPKI data integration into anomaly detection confidence scoring — RPKI-invalid anomalies receive higher severity
- Essential for MANRS compliance demonstrating commitment to routing security best practices
Engineered and operated by the GOLINE SOC & Network Engineering team.
Explore all RoutePulse features →